LWN.net Logo

ocsinventory-agent: insecure module search path

Package(s):ocsinventory-agent CVE #(s):CVE-2009-0667
Created:July 7, 2009 Updated:October 22, 2010
Description: From the Debian advisory: It was discovered that the ocsinventory-agent which is part of the ocsinventory suite, a hardware and software configuration indexing service, is prone to an insecure perl module search path. As the agent is started via cron and the current directory (/ in this case) is included in the default perl module path the agent scans every directory on the system for its perl modules. This enables an attacker to execute arbitrary code via a crafted ocsinventory-agent perl module placed on the system.
Alerts:
Fedora FEDORA-2010-16334 2010-10-14
Fedora FEDORA-2010-16335 2010-10-14
Debian DSA-1828-1 2009-07-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds