Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian: DSA-3942-1 High: Supervisor XML-RPC Command Injection

debian
Calendar Grey August 13, 2017
Debian Logo
Ubuntu: USN-5432-1 highlights a vulnerability in controller enabling unauthorized command execution via JSON-RPC interfaces.
Calum Hutton reported that the XML-RPC server in supervisor, a system for controlling process state, does not perform validation on requested XML-RPC methods, allowing an authentic...

Summary

The vulnerability has been fixed by disabling nested namespace lookup
entirely. supervisord will now only call methods on the object
registered to handle XML-RPC requests and not any child objects it may
contain, possibly breaking existing setups. No publicly available
plugins are currently known that use nested namespaces. Plugins that use
a single namespace will continue to work as before. Details can be found
on the upstream issue at
https://github.com/Supervisor/supervisor/issues/964 .

For the oldstable distribution (jessie), this problem has been fixed
in version 3.0r1-1+deb8u1.

For the stable distribution (stretch), this problem has been fixed in
version 3.3.1-1+deb9u1.

We recommend that you upgrade your supervisor packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: supervisor
CVE ID: CVE-2017-11610

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here