CVE-2011-3211

Publication date 16 September 2011

Last updated 24 July 2024


Ubuntu priority

Description

The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.

Status

Package Ubuntu Release Status
bcfg2 11.04 natty
Fixed 1.1.1-2ubuntu1.2
10.10 maverick
Fixed 0.9.6-0ubuntu2.1.10.10.1
10.04 LTS lucid
Fixed 0.9.6-0ubuntu2.1.10.04.1
8.04 LTS hardy
Fixed 0.9.5.7-1ubuntu0.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
bcfg2

Access our resources on patching vulnerabilities