Overview
Plesk Panel 11.0.9 and possibly earlier versions contains multiple privilege escalation vulnerabilities.
Description
Plesk Panel contains multiple privilege escalation vulnerabilities which may allow an attacker to run arbitrary code as the root user. Special-case rules in Plesk's custom version of Apache suexec allow execution of arbitrary code as an arbitrary user id above a certain minimum value. In addition, several administrative or system accounts have a user ID above this minimum.
|
Impact
An authenticated attacker maybe be able to escalate their privileges to root allowing them to run arbitrary code as the root user. |
Solution
Update |
Parallel's Plesk Panel advisory states the following workaround:
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 4.5 | E:U/RL:OF/RC:UC |
Environmental | 3.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Ronald Volgers of Pine Digital Security for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-0132, CVE-2013-0133 |
Date Public: | 2013-04-10 |
Date First Published: | 2013-04-10 |
Date Last Updated: | 2014-07-30 16:56 UTC |
Document Revision: | 25 |