CVE-2007-5360
published 2008-01-08CVE-2007-5360: Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1…
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
15.33%
96.4th percentile
Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openpegasus | management_server | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tog-pegasus pam authentication buffer overflow
vendor_redhat·2008-01-08·CVSS 7.5
CVE-2007-5360 [HIGH] tog-pegasus pam authentication buffer overflow
tog-pegasus pam authentication buffer overflow
Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.
Statement: Not vulnerable. This issue did not affect versions of tog-pegasus as shipped with Red Hat Enterprise Linux 4, or 5. For more details see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360
Red Hat
tog-pegasus pam authentication buffer overflow
vendor_redhat·2008-01-07·CVSS 7.5
CVE-2008-0003 [HIGH] CWE-121 tog-pegasus pam authentication buffer overflow
tog-pegasus pam authentication buffer overflow
Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.
Mitigation: The tog-pegasus package is not installed by default on Red Hat Enterprise Linux.
tog-pegasus supplied by Red Hat binds only to one port (as plain http is
disabled), port 5989. The default firewall installed by Red Hat Enterprise
Linux will block remote access to this port. In normal use it's unlikely you'd
want to have this port accessible outside of an intranet anyway, and it's likely
to be blocked by en
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
Red Hat
CVE-2008-0495: Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3
vendor_redhat·CVSS 7.5
CVE-2008-0495 [HIGH] CVE-2008-0495: Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3
Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.
Statement: We believe this issue is a duplicate of CVE-2007-5360. Not vulnerable. This issue did not affect versions of tog-pegasus as shipped with Red Hat Enterprise Linux 4, or 5. For more details see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360
GHSA
GHSA-79mv-qv9r-5fvw: Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Ser
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-5360 [CRITICAL] CWE-119 GHSA-79mv-qv9r-5fvw: Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Ser
Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.
GHSA
GHSA-9px5-84gc-9hrq: Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to us
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2008-0003 [HIGH] CWE-119 GHSA-9px5-84gc-9hrq: Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to us
Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5360 tog-pegasus pam authentication buffer overflow
bugzilla·2007-12-22·CVSS 7.5
CVE-2007-5360 [HIGH] CVE-2007-5360 tog-pegasus pam authentication buffer overflow
CVE-2007-5360 tog-pegasus pam authentication buffer overflow
VMWare reported a buffer overflow vulnerability in the PAM authentication code
in the OpenPegasus CIM management server. This vulnerability can be exploited
remotely and results in arbitrary code execution with the privileges of the
cimserver process.
Details in next comment.
Due to the nature of the bug, and the Red Hat changes to tog-pegasus package,
it's quite likely it has a much reduced impact, this will have to be investigated.
Current embargo is Dec 27th. I've asked for an extension to Jan 3rd at the
earliest.
Discussion:
There were some changes made to authentication code for Red Hat version, these
need to be checked
The sprintf is unfortunately not caught by fortify_source (because it's C++)
We do ship with a SEL
Bugzilla
CVE-2008-0003 tog-pegasus pam authentication buffer overflow
bugzilla·2007-12-22·CVSS 10.0
CVE-2008-0003 [CRITICAL] CVE-2008-0003 tog-pegasus pam authentication buffer overflow
CVE-2008-0003 tog-pegasus pam authentication buffer overflow
Whilst investigating a VMWare reported buffer overflow vulnerability (bug
#426568) in the PAM authentication code in the OpenPegasus CIM management server
that didn't affect Red Hat packages, I found another one that did.
This vulnerability can be exploited remotely and results in arbitrary code
execution with the privileges of the cimserver process. Note that we do ship
with a default SELinux policy for this package.
Current embargo is unset. Likely to be 2nd week of Jan 2008.
Discussion:
This is a problem inside PAMBasicAuthenticator::PAMCallback()
//
// copy the user password
//
resp[i]->resp = (char *)malloc(PAM_MAX_MSG_SIZE);
strcpy(resp[i]->resp, mydata->userPassword);
resp[i]->resp_retcode = 0;
break;
But mydata->us
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409http://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://secunia.com/advisories/28358http://secunia.com/advisories/28368http://secunia.com/advisories/28636http://secunia.com/advisories/29986http://securityreason.com/securityalert/3538http://www.attrition.org/pipermail/vim/2008-January/001879.htmlhttp://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2008/0063http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/1391/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360https://exchange.xforce.ibmcloud.com/vulnerabilities/39524http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409http://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://secunia.com/advisories/28358http://secunia.com/advisories/28368http://secunia.com/advisories/28636http://secunia.com/advisories/29986http://securityreason.com/securityalert/3538http://www.attrition.org/pipermail/vim/2008-January/001879.htmlhttp://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2008/0063http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/1391/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360https://exchange.xforce.ibmcloud.com/vulnerabilities/39524
2008-01-08
Published