Bug 517837 (CVE-2009-3042)
Summary: | OCS Inventory NG: SQL injection in machine blacklisting | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | fedora, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=147&cntnt01returnid=15 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-09-01 19:43:32 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jan Lieskovsky
2009-08-17 12:51:45 UTC
This issue affect the versions of ocsinventory package, as shipped with Fedora release of 10 and 11. This issue affect the versions of ocsinventory package, as shipped with Extra Packages for Enterprise Linux (EPEL-4 and EPEL-5) projects. Please fix. ocsinventory-1.02.1-3.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.fc11 ocsinventory-1.02.1-3.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.fc10 ocsinventory-1.02.1-3.el5 has been submitted as an update for Fedora EPEL 5. http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.el5 ocsinventory-1.02.1-3.el4 has been submitted as an update for Fedora EPEL 4. http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.el4 ocsinventory-1.02.1-3.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report. ocsinventory-1.02.1-3.el4 has been pushed to the Fedora EPEL 4 stable repository. If problems still persist, please make note of it in this bug report. ocsinventory-1.02.1-3.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. ocsinventory-1.02.1-3.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. *** Bug 519497 has been marked as a duplicate of this bug. *** Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3042 to the following vulnerability: Name: CVE-2009-3042 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042 Assigned: 20090901 Reference: BUGTRAQ:20090811 Sql injection in OCS Inventory NG Server 1.2.1 Reference: URL: http://www.securityfocus.com/archive/1/archive/1/505675/100/0/threaded Reference: FULLDISC:20090811 Sql injection in OCS Inventory NG Server 1.2.1 Reference: URL: http://seclists.org/fulldisclosure/2009/Aug/0143.html Reference: MILW0RM:9416 Reference: URL: http://www.milw0rm.com/exploits/9416 Reference: CONFIRM: http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=147&cntnt01returnid=15 Reference: SECUNIA:35311 Reference: URL: http://secunia.com/advisories/35311 SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040. |