[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] Re: CVE Request: Percona Toolkit automatic version check - remote code execution / in
From:       cve-assign () mitre ! org
Date:       2014-02-19 23:45:36
Message-ID: 201402192345.s1JNjawL029606 () linus ! mitre ! org
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> The configuration for what information PT tools should collect is not
> hardcoded in the scripts. Instead, every time it's downloaded from
> http://v.percona.com/. One of the possible parameters is a binary file
> name to be executed ... The configuration can also ask for any MySQL
> variable - not just the version string.

Use CVE-2014-2029 for this issue in which a plain HTTP session is
used, and a man-in-the-middle attack can lead to remote code execution
(or retrieving sensitive configuration information).


> When this option is enabled - and it is enabled by default(!) -
> various information ... are submitted to Percona along with the
> server's IP address ... without bringing it to user's attention or
> asking for their consent.

There is no CVE assignment specifically for the transmission of data
to Percona without user confirmation. This is potentially unwanted
behavior, but it does not seem that this a mistake (in the sense that
a developer was trying to implement a different behavior).

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTBUGWAAoJEKllVAevmvmsrgwH/1J2KvABlDmoC71Zz6KALdgc
/L/F6c8GpAR8A8tBlPf+J/O3vZfZMMZ7ey3sId5Ht8HvRxRiGoA/6mAE7/FCCd1y
pVq9ndmK5zUQ0VLeuHXXxDusyXdBB3PEcGefSMS5ZdzKv6ESQ7FgxoMX8IuvFF0p
sGZyJQUl/ZECzzHU4qxksAnuqatSlcfKVY4sGUP1j7DXhv6GLzlHPJke+6aRsIuU
Wrbh6/uL/8tDxctJCx0dn/7iSIjlV5XkgbLbR6aNiGrxIOmPNTqDLcJq8xzX5/+G
arXEuopxCc5O3pfix0PrnvzxjwfnFLNpoMop9hPVhsww9t2HimIj2YcCRZ/aQ2Q=
=s5z5
-----END PGP SIGNATURE-----
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic