Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 11.04: USN-1137-1 Moderate: Eucalyptus Command Injection

ubuntu
Calendar Grey May 26, 2011
Scroller Ubuntu
This announcement addresses a vulnerability in Eucalyptus on Ubuntu platforms that permits remote attackers to execute commands.
An attacker could send crafted input to Eucalyptus to run commands as a valid user.

Summary

An attacker could send crafted input to Eucalyptus to run commands as

a valid user.

Software Description:

- eucalyptus: Elastic Utility Computing Architecture

- rampart: Apache web services security engine

Details:

Juraj Somorovsky, Jorg Schwenk, Meiko Jensen and Xiaofeng Lou discovered

that Eucalyptus did not properly validate SOAP requests. An unauthenticated

remote attacker could exploit this to submit arbitrary commands to the

Eucalyptus SOAP interface in the context of an authenticated user.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  eucalyptus-cloud                2.0.1+bzr1256-0ubuntu4.1
  librampart0                     1.3.0-1ubuntu2.1

Ubuntu 10.10:
  eucalyptus-cloud                2.0+bzr1241-0ubuntu4.2
  librampart0                     1.3.0-1ubuntu1.1

Ubuntu 10.04 LTS:
  eucalyptus-cloud                1.6.2-0ubuntu30.5
  librampart0                     1.3.0-0ubuntu7.1

In general, a standard system update will make all the necessary changes.

References

CVE-2011-0730

May 26, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.