Title : Fedora Security Update Fixes Cobbler Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-3203 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-20
Technical Description
A vulnerability has been identified in Fedora, which could be exploited by malicious users to compromise a vulnerable system. This issue is caused by an unspecified error in a Cobbler, which could allow a malicious CobblerWeb user to import a Python module via a web-edited Cheetah template and run commands as root.