Bug 1072314 (CVE-2017-10906) - [security:logging] CVE-2017-10906: fluentd: Escape sequence injection in filter_parser.rb:filter_stream can lead to arbitrary command execution when processing logs
Summary: [security:logging] CVE-2017-10906: fluentd: Escape sequence injection in filt...
Status: RESOLVED FIXED
Alias: CVE-2017-10906
Product: openSUSE Distribution
Classification: openSUSE
Component: Other (show other bugs)
Version: Leap 42.3
Hardware: Other Other
: P5 - None : Minor (vote)
Target Milestone: ---
Assignee: Klaus Kämpf
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/196385/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-12-12 07:22 UTC by Marcus Meissner
Modified: 2017-12-12 08:09 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-12-12 07:22:47 UTC
rh#1524783

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through
0.12.40 may allow an attacker to change the terminal UI or execute arbitrary
commands on the device via unspecified vectors.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1524783
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-10906
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10906
https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes
https://github.com/fluent/fluentd/pull/1733
https://jvn.jp/en/vu/JVNVU95124098/index.html
Comment 1 Klaus Kämpf 2017-12-12 08:09:08 UTC
Package updated to 1.0.0