Novell Home

CVE-2007-5360

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2007-5360 at MITRE

Description

Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.

NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 350519

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SLE SDK 10 SP1 for IBM iSeries and IBM pSeries
SLE SDK 10 SP1 for IBM zSeries
SLE SDK 10 SP1 for IPF
SLE SDK 10 SP1 for X86-64
SLE SDK 10 SP1 for x86
  • tog-pegasus >= 2.5.1-2.15
  • tog-pegasus-devel >= 2.5.1-2.15
  • tog-pegasus-test >= 2.5.1-2.15
Builds
ZYPP Patch Nr: 4872

© 2012 Novell