Improper access control in Net-Server - CVE-2013-1841

 

Improper access control in Net-Server - CVE-2013-1841

Published: March 16, 2023


Vulnerability identifier: #VU73771
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1841
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due Net-Server does not check if the hostname resolves to the source IP address when the reverse-lookups option is enabled. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Net-Server
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Basesystem Module
openSUSE Leap
perl-Net-Server

How to mitigate CVE-2013-1841

Install updates from vendor's website.

perl-Net-Server - addressed in versions 2.007-5.3.1, 2.009-150000.3.3.1

External References

Related Security Bulletins