oss-sec mailing list archives
Re: CVE Request: Percona Toolkit automatic version check - remote code execution / information leak
From: cve-assign () mitre org
Date: Wed, 19 Feb 2014 18:45:36 -0500 (EST)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
The configuration for what information PT tools should collect is not hardcoded in the scripts. Instead, every time it's downloaded from http://v.percona.com/. One of the possible parameters is a binary file name to be executed ... The configuration can also ask for any MySQL variable - not just the version string.
Use CVE-2014-2029 for this issue in which a plain HTTP session is used, and a man-in-the-middle attack can lead to remote code execution (or retrieving sensitive configuration information).
When this option is enabled - and it is enabled by default(!) - various information ... are submitted to Percona along with the server's IP address ... without bringing it to user's attention or asking for their consent.
There is no CVE assignment specifically for the transmission of data to Percona without user confirmation. This is potentially unwanted behavior, but it does not seem that this a mistake (in the sense that a developer was trying to implement a different behavior). - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJTBUGWAAoJEKllVAevmvmsrgwH/1J2KvABlDmoC71Zz6KALdgc /L/F6c8GpAR8A8tBlPf+J/O3vZfZMMZ7ey3sId5Ht8HvRxRiGoA/6mAE7/FCCd1y pVq9ndmK5zUQ0VLeuHXXxDusyXdBB3PEcGefSMS5ZdzKv6ESQ7FgxoMX8IuvFF0p sGZyJQUl/ZECzzHU4qxksAnuqatSlcfKVY4sGUP1j7DXhv6GLzlHPJke+6aRsIuU Wrbh6/uL/8tDxctJCx0dn/7iSIjlV5XkgbLbR6aNiGrxIOmPNTqDLcJq8xzX5/+G arXEuopxCc5O3pfix0PrnvzxjwfnFLNpoMop9hPVhsww9t2HimIj2YcCRZ/aQ2Q= =s5z5 -----END PGP SIGNATURE-----
Current thread:
- CVE Request: Percona Toolkit automatic version check - remote code execution / information leak Marcus Meissner (Feb 18)
- Re: CVE Request: Percona Toolkit automatic version check - remote code execution / information leak cve-assign (Feb 19)