Zenoss Core version check Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Zenoss Core <5 Beta 3
Description:
CVE (CAN) ID: CVE-2014-6261
Zenoss Core is an open-source IT monitoring solution.
In versions earlier than Zenoss Core 5 Beta 3, the Check For Updates function was not correctly executed. A security vulnerability exists. Remote attackers can exploit this vulnerability to execute arbitrary code by deceiving the callhome server or deploying a website.
<* Source: Ryan Koppenhaver
Link: http://www.kb.cert.org/vuls/id/449452
*>
Suggestion:
Vendor patch:
Zenoss
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://docs.google.com/spreadsheets/d/1dHAc4PxUbs-4Dxzm1wSCE0sMz5UCMY6SW3PlMHSyuuQ/edit? Usp = sharing
This article permanently updates the link address: