CVE-2011-0730
Summary
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Impact & exploitability
AV:N/AC:L/Au:S/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://launchpadlibrarian.net/72472626/eucalyptus_2.0.1%2Bbzr1256-0ubuntu5_2.0.1%2Bbzr1256-0ubuntu6.diff.gz ↗
Additional information
- NVD record
- http://launchpadlibrarian.net/72472626/eucalyptus_2.0.1%2Bbzr1256-0ubuntu5_2.0.1%2Bbzr1256-0ubuntu6.diff.gzPatch
- https://launchpad.net/ubuntu/+source/eucalyptus/+changelogPatch
- http://open.eucalyptus.com/wiki/esa-02Advisory
- http://secunia.com/advisories/44705Advisory
- http://www.securityfocus.com/bid/48000Advisory
- http://www.ubuntu.com/usn/USN-1137-1Advisory
- https://bugs.launchpad.net/bugs/746101Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67670Advisory