Debian Security Update DSA-3942 supervisor - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,785
Reaction score
74
Credits
-1,257
Calum Hutton reported that the XML-RPC server in supervisor, a system for controlling process state, does not perform validation on requested XML-RPC methods, allowing an authenticated client to send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server as the same user as supervisord.

Continue reading...
 


Follow Linux.org

Members online


Top