APP: Sophos Web Protection Appliance Sblistpack Arbitrary Command Execution
This signature detects attempts to exploit a known vulnerability against Sophos Web Protection. A successful attack can lead to arbitrary code execution
Extended Description
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
Affected Products
Sophos web_appliance
References
BugTraq: 62263
CVE: CVE-2013-4983
URL: http://www.coresecurity.com/advisories/sophos-web-protection-appliance-multiple-vulnerabilities
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Sophos
10.0
7.2