Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 517837 - (CVE-2009-3042) OCS Inventory NG: SQL injection in machine blacklisting
OCS Inventory NG: SQL injection in machine blacklisting
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
http://www.ocsinventory-ng.org/index....
impact=moderate,reported=20090817,pub...
: Security
: 519497 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-08-17 08:51 EDT by Jan Lieskovsky
Modified: 2009-09-01 15:43 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-01 15:43:32 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2009-08-17 08:51:45 EDT
A SQL injection flaw was found in the way OCS Inventory NG used to process
machine blacklisting based on MAC addresses. A remote attacker(valid OCS NG
user) could issue a specially-crafted HTTP request, leading to sensitive
information disclosure or, potentially, to arbitrary SQL code execution.

References:
-----------
http://seclists.org/fulldisclosure/2009/Aug/0143.html
http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=147&cntnt01returnid=15

PoC:
----
http://localhost/ocsreports/machine.php?systemid=1)%20union%20select%201,2,user( ),3,5,6,7,8,9,10,11,12,passwd,14,15,16,17,18,id,20,21,22,23,24,25,26,27,27,version()%20from%20operators%20--

Upstream patch:
---------------
http://ocsinventory.svn.sourceforge.net/viewvc/ocsinventory/branches/server/1.02/ocsreports/machine.php?r1=1762&r2=1829&view=patch

Credit:
-------
Guilherme Marinheiro


CVE request:
------------
http://www.openwall.com/lists/oss-security/2009/08/17/3
Comment 1 Jan Lieskovsky 2009-08-17 08:54:41 EDT
This issue affect the versions of ocsinventory package, as shipped with
Fedora release of 10 and 11.

This issue affect the versions of ocsinventory package, as shipped with
Extra Packages for Enterprise Linux (EPEL-4 and EPEL-5) projects.

Please fix.
Comment 2 Fedora Update System 2009-08-17 11:10:35 EDT
ocsinventory-1.02.1-3.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.fc11
Comment 3 Fedora Update System 2009-08-17 11:11:07 EDT
ocsinventory-1.02.1-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.fc10
Comment 4 Fedora Update System 2009-08-17 11:11:40 EDT
ocsinventory-1.02.1-3.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.el5
Comment 5 Fedora Update System 2009-08-17 11:13:42 EDT
ocsinventory-1.02.1-3.el4 has been submitted as an update for Fedora EPEL 4.
http://admin.fedoraproject.org/updates/ocsinventory-1.02.1-3.el4
Comment 6 Fedora Update System 2009-08-19 11:58:54 EDT
ocsinventory-1.02.1-3.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2009-08-19 11:59:07 EDT
ocsinventory-1.02.1-3.el4 has been pushed to the Fedora EPEL 4 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2009-08-20 17:00:09 EDT
ocsinventory-1.02.1-3.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 9 Fedora Update System 2009-08-20 17:03:54 EDT
ocsinventory-1.02.1-3.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 10 Vincent Danen 2009-08-27 11:02:50 EDT
*** Bug 519497 has been marked as a duplicate of this bug. ***
Comment 11 Vincent Danen 2009-09-01 15:43:32 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3042 to
the following vulnerability:

Name: CVE-2009-3042
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042
Assigned: 20090901
Reference: BUGTRAQ:20090811 Sql injection in OCS Inventory NG Server 1.2.1
Reference: URL: http://www.securityfocus.com/archive/1/archive/1/505675/100/0/threaded
Reference: FULLDISC:20090811 Sql injection in OCS Inventory NG Server 1.2.1
Reference: URL: http://seclists.org/fulldisclosure/2009/Aug/0143.html
Reference: MILW0RM:9416
Reference: URL: http://www.milw0rm.com/exploits/9416
Reference: CONFIRM: http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=147&cntnt01returnid=15
Reference: SECUNIA:35311
Reference: URL: http://secunia.com/advisories/35311

SQL injection vulnerability in machine.php in Open Computer and
Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute
arbitrary SQL commands via the systemid parameter, a different vector
than CVE-2009-3040.

Note You need to log in before you can comment on or make changes to this bug.