Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian 5.0 Lenny DSA-1828-1 Critical: Ocsinventory-Agent Exec Threat

debian
Calendar Grey July 7, 2009
Scroller Debian
Learn about the vulnerabilities linked to an improperly secured Perl module path in ocsinventory-agent. Explore suggested solutions and enhancements to mitigate these risks.
It was discovered that the ocsinventory-agent which is part of the ocsinventory suite, a hardware and software configuration indexing service, is prone to an insecure perl module s...

Summary


It was discovered that the ocsinventory-agent which is part of the
ocsinventory suite, a hardware and software configuration indexing service,
is prone to an insecure perl module search path. As the agent is started
via cron and the current directory (/ in this case) is included in the
default perl module path the agent scans every directory on the system
for its perl modules. This enables an attacker to execute arbitrary code
via a crafted ocsinventory-agent perl module placed on the system.


The oldstable distribution (etch) does not contain ocsinventory-agent.

For the stable distribution (lenny), this problem has been fixed in
version 1:0.0.9.2repack1-4lenny1.

For the testing distribution (squeeze), this problem has been fixed in
version 1:0.0.9.2repack1-5

For the unstable distribution (sid), this problem has been fixed in
version 1:0.0.9.2repack1-5.


We recommend that you upgrade your ocsinventory-agent packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: ocsinventory-agent
CVE ID: CVE-2009-0667

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.