Oval Definition:oval:com.ubuntu.precise:def:20142029000
Revision Date:2014-02-21Version:1
Title:CVE-2014-2029 on Ubuntu 12.04 LTS (precise) - medium.
Description:Percona Toolkit 2.1 introduced --version-check to warn user about known vulnerabilities in the local MySQL instance and to check for PT updates. The configuration for what information PT tools should collect is not hardcoded in the scripts. Instead, every time it's downloaded from http://v.percona.com/. One of the possible parameters is a binary file name to be executed, i.e. Percona can remotely execute arbitrary command.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-2029
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'percona-toolkit' package in precise is not affected (note: '1.0.1-3').
  • BACK