Apache Thrift Remote Command Injection Vulnerability (CVE-2016-5397)
Apache Thrift Remote Command Injection Vulnerability (CVE-2016-5397)
Release date:
Updated on:
Affected Systems:
Apache Group Thrift <= 0.9.3
Description:
Bugtraq id: 103025
CVE (CAN) ID: CVE-2016-5397
Apache Thrift is an efficient remote service calling framework implemented by Facebook that supports multiple programming languages.
Apache Thrift 0.9.3 and earlier versions have the remote command injection vulnerability. Attackers can exploit this vulnerability to inject and execute arbitrary code in the context of the affected application.
<* Source: Jake Farrell
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3E
Http://www.apache.org/
Https://issues.apache.org/jira/browse/THRIFT-3893
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151151.htm