Vulnerability Note VU#857153
OPeNDAP code execution vulnerability
Overview
OPeNDAP server version 3 contains a vulnerability that allows an attacker to execute comands on the server.
Description
From the OPenNDAP website: OPeNDAP provides software which makes local data accessible to remote locations regardless of local storage format. OPeNDAP also provides tools for transforming existing applications into OPeNDAP clients (i.e., enabling them to remotely access OPeNDAP served data). |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary commands. |
Solution
Apply a patch |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| OPeNDAP, Inc. | Affected | - | 30 Apr 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.opendap.org/
- http://www.opendap.org/download/hyrax.html
- http://www.opendap.org/server3-patch-04.27.2007.txt
- http://www.cert.org/tech_tips/win-UNIX-system_compromise.html
- http://secunia.com/advisories/25060/
Credit
Thanks to the OPeNDAP team for information used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 14 May 2007
- Date First Published: 30 Apr 2007
- Date Last Updated: 18 May 2007
- Severity Metric: 2.16
- Document Revision: 18
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.