Описание
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Отчет
This vulnerability is rated Moderate for Red Hat because it requires a malicious actor to convince libnbd to open a specially crafted URI. This leads to arbitrary code execution due to improper handling of non-standard hostnames starting with '-o' as SSH arguments, executing code with the privileges of the user running libnbd.
Меры по смягчению последствий
To mitigate this issue, ensure that applications utilizing libnbd do not process Uniform Resource Identifiers (URIs) from untrusted or unverified sources. This vulnerability requires a malicious actor to convince libnbd to open a specially crafted URI, therefore restricting the sources of URIs processed by libnbd can reduce exposure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libnbd | Affected | ||
| Red Hat Enterprise Linux 8 | virt:rhel/libnbd | Not affected | ||
| Red Hat Enterprise Linux 9 | libnbd | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-apiserver | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-apiserver-rhel9 | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-cloner | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-cloner-rhel9 | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-controller | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-controller-rhel9 | Not affected | ||
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/virt-cdi-importer | Not affected |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
A flaw was found in libnbd. A malicious actor could exploit this by co ...
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Уязвимость набора инструментов для работы с Network Block Device Libnbd, связанная с внедрением или модификацией аргумента, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
4.8 Medium
CVSS3