|
|
Subscribe / Log in / New account

beanstalkd: unauthorized execution of beanstalk client commands

Package(s):beanstalkd CVE #(s):
Created:June 22, 2010 Updated:June 23, 2010
Description: From the Red Hat bugzilla:

Graham Barr reported that beanstalkd v1.4.5 and earlier, improperly sanitized job data, sent together with put command from client. A remote attacker, providing a specially-crafted job data in request, could use this flaw to bypass intended beanstalk client commands dispatch mechanism, leading to unauthorized execution of beanstalk client commands.

Alerts:
Fedora FEDORA-2010-9656 beanstalkd 2010-06-07
Fedora FEDORA-2010-9570 beanstalkd 2010-06-07

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds