CVE-2012-2395
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
Cobbler subject to Command Injection
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://github.com/cobbler/cobbler/commit/6d9167e5da44eca56bdf42b5776097a6779aaadf
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | cobbler | <2.6.0 | 2.6.0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| michael_dehaan | cobbler | 2.2.0 | |
References
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00000.html
- http://www.openwall.com/lists/oss-security/2012/05/23/18
- http://www.openwall.com/lists/oss-security/2012/05/23/4
- http://www.osvdb.org/82458
- http://www.securityfocus.com/bid/53666
- https://bugs.launchpad.net/ubuntu/+source/cobbler/+bug/978999
- https://github.com/cobbler/cobbler/commit/6d9167e5da44eca56bdf42b5776097a6779aaadf
- https://github.com/cobbler/cobbler/issues/141
- https://nvd.nist.gov/vuln/detail/CVE-2012-2395
- https://github.com/cobbler/cobbler
- https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00016.html
- https://lists.opensuse.org/opensuse-security-announce/2012-07/msg00000.html
- https://web.archive.org/web/20120712025653/http://www.securityfocus.com/bid/53666
- https://www.openwall.com/lists/oss-security/2012/05/23/18
- https://www.openwall.com/lists/oss-security/2012/05/23/4
- https://www.osvdb.org/82458
Verify integrity in audit chain (admin only). AS-IS.