← Back

CVE-2019-19041

nvd nist
Published: Nov 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by the underlying system. It is possible to achieve this by modifying the values in the files.SUM file (which are used for integrity control) and injecting malicious code into the upgrade.sh file.

Affected (2)

Products: Xorur: Lpar2rrd, Stor2rrd
2 products
Lpar2rrd
Stor2rrd
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.11
Version 2.61
Running on/withPlatform Versions
Xorur
Xorur
Version 2.41

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory

Timeline

No history available yet.