Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CGI:WEB-SERVER-CGI-RCE

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

EmbedThis GoAhead Web Server Remote Code Execution

Release Date

2018/01/03

Update Number

3023

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: EmbedThis GoAhead Web Server Remote Code Execution


This signature detects attempts to exploit a known vulnerability against EmbedThis GoAhead Web Server. A successful attack can lead to arbitrary code execution under the security context of the server process

Extended Description

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

Affected Products

  • Embedthis goahead -
  • Embedthis goahead 2.1.5
  • Embedthis goahead 2.1.8
  • Embedthis goahead 2.5.0
  • Embedthis goahead 3.0.0
  • Embedthis goahead 3.1.0
  • Embedthis goahead 3.1.1
  • Embedthis goahead 3.1.2
  • Embedthis goahead 3.1.3
  • Embedthis goahead 3.3.0
  • Embedthis goahead 3.3.1
  • Embedthis goahead 3.3.2
  • Embedthis goahead 3.3.3
  • Embedthis goahead 3.3.4
  • Embedthis goahead 3.3.5
  • Embedthis goahead 3.3.6
  • Embedthis goahead 3.4.0
  • Embedthis goahead 3.4.1
  • Embedthis goahead 3.4.10
  • Embedthis goahead 3.4.11
  • Embedthis goahead 3.4.12
  • Embedthis goahead 3.4.2
  • Embedthis goahead 3.4.3
  • Embedthis goahead 3.4.4
  • Embedthis goahead 3.4.5
  • Embedthis goahead 3.4.6
  • Embedthis goahead 3.4.7
  • Embedthis goahead 3.4.8
  • Embedthis goahead 3.4.9
  • Embedthis goahead 3.5.0
  • Embedthis goahead 3.6.0
  • Embedthis goahead 3.6.1
  • Embedthis goahead 3.6.2
  • Embedthis goahead 3.6.3
  • Embedthis goahead 3.6.4

References

  • CVE: CVE-2017-17562
  • URL: https://embedthis.com/blog/posts/2017/goahead-security-update.html
  • URL: https://www.elttam.com.au/blog/goahead/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out