lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <1407807279.34767.YahooMailNeo@web141002.mail.bf1.yahoo.com>
Date: Mon, 11 Aug 2014 18:34:39 -0700
From: Gregory Pickett <gpickett71@...oo.com>
To: Fulldisclosure <fulldisclosure@...lists.org>,
	Bugtraq <bugtraq@...urityfocus.com>
Subject: [FD] CVE-2014-5035 - Opendaylight Vulnerable to Local and Remote
	File Inclusion in the Netconf (TCP) Service


Title
===================
Opendaylight Vulnerable to Local and Remote File Inclusion in the Netconf (TCP) Service

Summary
===================
Opendaylight (www.opendaylight.com) is vulnerable to Local and Remote File Inclusion in the Netconf (TCP) Service via an External Entity Injection (XXE).  Opendaylight’s netconf service, when receiving an XML-RPC message, will process any external entities referenced in that message, local or remote.  And will do so using its own running credentials which are root.  So by injecting a reference to a local file, you can extract any file you like from the running system including the shadow file which can be leveraged by an attacker to perform an offline password attack.

Affected Products
===================
Opendaylight 1.0 (Hydrogen) – Base, Virtualization, and Service Provider Editions

CVE
===================
CVE-2014-5035

Details
===================
“To Be Released Later”

Impact
===================
Information Disclosure.  Disclosure of hashed system credentials, which enables mounting of offline password attacks.  Eventual disclosure of clear-text system credentials.

Credits
===================
Gregory Pickett (@shogun7273), Hellfire Security


---------- 
Gregory Pickett, CISSP, GCIA, GPEN

_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ