← Back

CVE-2009-4261

nvd nist
Published: Dec 21, 2009Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."

Affected (11)

Products: Roman Marxer: Ganeti
1 product
Ganeti
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Roman Marxer
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 2.0.0
Version 2.0.0 rc1
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.1.0 rc1

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.