Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 27 Nov 2014 12:53:46 +0100
From: Damien Cauquil <d.cauquil@...dream.com>
To: oss-security@...ts.openwall.com
CC: n.chatelain@...dream.com
Subject: CVE Request: Multiple vulnerabilities in Centreon <= 2.5.3

We found two vulnerabilities in Centreon <= 2.5.3:

1. Unauthenticated remote command execution

This vulnerability allows an unauthenticated user to execute arbitrary commands on the remote system.

2. Information disclosure (local)

A specific command-line utility allows local users to escalate privileges and retrieve sensitive files on the system, such as /etc/shadow. This vulnerability provides a root user access on files (read only). 


Vendor was notified and most of the fixes were implemented and will be available in the next release (coming very soon).


We would like to request 2 CVEs for these vulnerabilities.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.