vendor:
CFEngine2
by:
kokaninATdtors.net
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CFEngine2
Affected Version From: cfengine2-2.0.3
Affected Version To: cfengine2-2.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:cfengine:cfengine2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 4.8-RELEASE
2003
DSR-cfengine.pl
DSR-cfengine.pl is a perl script which exploits a buffer overflow vulnerability in cfengine2-2.0.3 from freebsd ports. The bug was discovered by nick cleaton and tested on FreeBSD 4.8-RELEASE. The exploit sends a malicious payload to the vulnerable host on the specified port, which then allows the attacker to execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of cfengine2-2.0.3 from freebsd ports.