oss-sec mailing list archives
CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3
From: Damien Cauquil <d.cauquil () sysdream com>
Date: Thu, 27 Nov 2014 12:53:46 +0100
We found two vulnerabilities in Centreon <= 2.5.3: 1. Unauthenticated remote command execution This vulnerability allows an unauthenticated user to execute arbitrary commands on the remote system. 2. Information disclosure (local) A specific command-line utility allows local users to escalate privileges and retrieve sensitive files on the system, such as /etc/shadow. This vulnerability provides a root user access on files (read only). Vendor was notified and most of the fixes were implemented and will be available in the next release (coming very soon). We would like to request 2 CVEs for these vulnerabilities.
Current thread:
- CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3 Damien Cauquil (Nov 27)
- Re: CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3 Henri Salo (Nov 27)
- Re: CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3 Damien Cauquil (Nov 27)
- <Possible follow-ups>
- CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3 Damien Cauquil (Nov 27)
- Re: CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3 Henri Salo (Nov 27)