git: beb077ea2af5 - main - security/vuxml: Add security/caldera and security/caldera4 vulnerabilities
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 06 Mar 2025 05:31:35 UTC
The branch main has been updated by acm: URL: https://cgit.FreeBSD.org/ports/commit/?id=beb077ea2af596d32ad74c590792e9b3766d6909 commit beb077ea2af596d32ad74c590792e9b3766d6909 Author: Jose Alonso Cardenas Marquez <acm@FreeBSD.org> AuthorDate: 2025-03-06 05:30:10 +0000 Commit: Jose Alonso Cardenas Marquez <acm@FreeBSD.org> CommitDate: 2025-03-06 05:30:10 +0000 security/vuxml: Add security/caldera and security/caldera4 vulnerabilities Obtained from: https://github.com/mitre/caldera/pull/3129 --- security/vuxml/vuln/2025.xml | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 37c4583d5275..8baadd853048 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,40 @@ + <vuln vid="d8bd20ae-fa48-11ef-ab7a-ace2d30de67a"> + <topic>caldera -- Remote Code Execution</topic> + <affects> + <package> + <name>caldera</name> + <range><lt>5.2.0</lt></range> + </package> + <package> + <name>caldera4</name> + <range><le>4.2.0</le></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>MITRE Caldera contributor report:</p> + <blockquote cite="https://github.com/mitre/caldera/pull/3129"> + <p>In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, + a Remote Code Execution (RCE) vulnerability was found in the dynamic + agent (implant) compilation functionality of the server. This allows + remote attackers to execute arbitrary code on the server that Caldera + is running on via a crafted web request to the Caldera server API used + for compiling and downloading of Caldera's Sandcat or Manx agent + (implants). This web request can use the gcc -extldflags linker flag + with sub-commands.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2025-27364</cvename> + <url>https://nvd.nist.gov/vuln/detail/CVE-2025-27364</url> + </references> + <dates> + <discovery>2025-02-16</discovery> + <entry>2025-03-06</entry> + </dates> + </vuln> + <vuln vid="cb98d018-f9f5-11ef-a398-00e081b7aa2d"> <topic>jenkins -- multiple vulnerabilities</topic> <affects>