Command Injection - CVE-2014-8990
Published: December 5, 2014 / Updated: August 3, 2020
Vulnerability identifier: #VU33063
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8990
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Affected software
Gentoo Linux
Fedora
yaml (Alpine package)
qemu (Alpine package)
docker (Alpine package)
zoneminder (Alpine package)
munin (Alpine package)
lsyncd (Alpine package)
graphviz (Alpine package)
lsyncd
Fedora
yaml (Alpine package)
qemu (Alpine package)
docker (Alpine package)
zoneminder (Alpine package)
munin (Alpine package)
lsyncd (Alpine package)
graphviz (Alpine package)
lsyncd
How to mitigate CVE-2014-8990
Install update from vendor's website.
yaml (Alpine package) - addressed in versions 0.1.6-r1, 0.1.7-r0
qemu (Alpine package) - addressed in versions 1.6.2-r4, 2.1.2-r1, 2.1.2-r2, 2.5.0-r0
docker (Alpine package) - update to 1.12.6-r0
zoneminder (Alpine package) - update to 1.30.2-r0
munin (Alpine package) - update to 2.0.33-r0
lsyncd (Alpine package) - update to 2.1.5-r3
graphviz (Alpine package) - update to 2.40.1-r0
lsyncd - addressed in versions 2.1.4-4.el5.1.1, 2.1.4-4.el6.1.1, 2.1.5-0.el6, 2.1.5-6.el7, 2.1.5-6.fc21
- update to 2.11-8ubuntu4
qemu (Alpine package) - addressed in versions 1.6.2-r4, 2.1.2-r1, 2.1.2-r2, 2.5.0-r0
docker (Alpine package) - update to 1.12.6-r0
zoneminder (Alpine package) - update to 1.30.2-r0
munin (Alpine package) - update to 2.0.33-r0
lsyncd (Alpine package) - update to 2.1.5-r3
graphviz (Alpine package) - update to 2.40.1-r0
lsyncd - addressed in versions 2.1.4-4.el5.1.1, 2.1.4-4.el6.1.1, 2.1.5-0.el6, 2.1.5-6.el7, 2.1.5-6.fc21
- update to 2.11-8ubuntu4
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145114.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145131.html
- http://secunia.com/advisories/62321
- http://www.debian.org/security/2015/dsa-3130
- http://www.openwall.com/lists/oss-security/2014/11/19/1
- http://www.openwall.com/lists/oss-security/2014/11/20/5
- http://www.securityfocus.com/bid/71179
- https://github.com/axkibe/lsyncd/commit/18f02ad013b41a72753912155ae2ba72f2a53e52
- https://github.com/axkibe/lsyncd/commit/e6016b3748370878778b8f0b568d5281cc248aa4
- https://github.com/axkibe/lsyncd/issues/220
- https://security.gentoo.org/glsa/201702-05
Related Security Bulletins
- Command Injection in Aconf
- Command Injection in Aconf
- Command Injection in lsyncd (Alpine package)
- Command Injection in Aconf
- Gentoo update for Lsyncd
- Fedora EPEL 7 update for lsyncd
- Fedora 21 update for lsyncd
- Fedora EPEL 6 update for lsyncd
- Fedora EPEL 5 update for lsyncd
- Fedora EPEL 6 update for lsyncd