Overview
The BES daemon in OPeNDAP server version 4 contains a vulnerability. This vulnerability may allow an attacker to execute arbitrary commands, or upload files to a remote server.
Description
OPeNDAP is a software package designed to help researchers exchange data sets that are stored in different formats. The most recent version of OPeNDAP is server 4, or Hyrax. The Hyrax server includes a daemon called BES. From the BES download page: |
Impact
An attacker to execute arbitrary commands on a vulnerable server. |
Solution
Upgrade |
Restrict access
|
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
| Temporal | 0 | E:ND/RL:ND/RC:ND |
| Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to NCIRT labs for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | None |
| Severity Metric: | 2.42 |
| Date Public: | 2007-05-14 |
| Date First Published: | 2007-05-18 |
| Date Last Updated: | 2007-05-21 19:04 UTC |
| Document Revision: | 18 |