|
|
|
![]() |
Vulnerability Note VU#857153OPeNDAP code execution vulnerabilityOverviewOPeNDAP server version 3 contains a vulnerability that allows an attacker to execute comands on the server.I. DescriptionFrom the OPenNDAP website:OPeNDAP provides software which makes local data accessible to remote locations regardless of local storage format. OPeNDAP also provides tools for transforming existing applications into OPeNDAP clients (i.e., enabling them to remotely access OPeNDAP served data). II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary commands.III. SolutionApply a patchThe OPeNDAP team has released a patch to address this issue. Users are encouraged to apply the patch as soon as possible.
References
Thanks to the OPeNDAP team for information used in this report. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||