Upstream information
Description
Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 763610 SUSE Security Advisories:- SUSE-SU-2012:0814-1, published Tue, 3 Jul 2012 16:08:22 +0200 (CEST)
- openSUSE-SU-2012:0655-1, published Tue, 29 May 2012 15:08:19 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Manager Client Tools for SLE 11 SP1 |
| Builds SAT Patch Nr: 6378 |
| SUSE Manager 1.2 for SLE 11 SP1 |
| Builds SAT Patch Nr: 6378 |
