VDB
CVE-2011-3211
CVE-2011-3211
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.
EPSS 2.38% · 85.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
2.38%
85.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| bcfg2 | bcfg2 | 0, 0.3.1, 0.4 |
Timeline
- Sep 15, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- https://github.com/solj/bcfg2/commit/f4a35efec1b6a1e54d61cf1b8bfc83dd1d89eef7 url
- https://bugzilla.redhat.com/show_bug.cgi?id=736279 url
- 49414 vdb
- 46042 third-party-advisory
- DSA-2302 vendor-advisory
- FEDORA-2011-12303 vendor-advisory
- 45926 third-party-advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640028 url
- [bcfg-dev] 20110816 Security flaw in 1.1.x; testers wanted mailing-list
- 45807 third-party-advisory
- [oss-security] 20110906 Re: CVE request for bcfg2 (remote root) mailing-list
- FEDORA-2011-12298 vendor-advisory
- https://github.com/solj/bcfg2/commit/46795ae451ca6ede55a0edeb726978aef4684b53 url
- [oss-security] 20110901 CVE request for bcfg2 (remote root) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2011-3211 advisory