template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cobbler | Michael_dehaan | * | 2.0.4 (including) |
| Cobbler | Michael_dehaan | 0.1.1.7 (including) | 0.1.1.7 (including) |
| Cobbler | Michael_dehaan | 0.2.1 (including) | 0.2.1 (including) |
| Cobbler | Michael_dehaan | 0.2.2 (including) | 0.2.2 (including) |
| Cobbler | Michael_dehaan | 0.2.3 (including) | 0.2.3 (including) |
| Cobbler | Michael_dehaan | 0.2.5 (including) | 0.2.5 (including) |
| Cobbler | Michael_dehaan | 0.2.7 (including) | 0.2.7 (including) |
| Cobbler | Michael_dehaan | 0.2.8 (including) | 0.2.8 (including) |
| Cobbler | Michael_dehaan | 0.2.9 (including) | 0.2.9 (including) |
| Cobbler | Michael_dehaan | 0.3.0 (including) | 0.3.0 (including) |
| Cobbler | Michael_dehaan | 0.3.1 (including) | 0.3.1 (including) |
| Cobbler | Michael_dehaan | 0.3.3 (including) | 0.3.3 (including) |
| Cobbler | Michael_dehaan | 0.3.4 (including) | 0.3.4 (including) |
| Cobbler | Michael_dehaan | 0.3.5 (including) | 0.3.5 (including) |
| Cobbler | Michael_dehaan | 0.3.6 (including) | 0.3.6 (including) |
| Cobbler | Michael_dehaan | 0.3.7 (including) | 0.3.7 (including) |
| Cobbler | Michael_dehaan | 0.3.9 (including) | 0.3.9 (including) |
| Cobbler | Michael_dehaan | 0.4.0 (including) | 0.4.0 (including) |
| Cobbler | Michael_dehaan | 0.4.2 (including) | 0.4.2 (including) |
| Cobbler | Michael_dehaan | 0.4.3 (including) | 0.4.3 (including) |
| Cobbler | Michael_dehaan | 0.4.5 (including) | 0.4.5 (including) |
| Cobbler | Michael_dehaan | 0.4.6 (including) | 0.4.6 (including) |
| Cobbler | Michael_dehaan | 0.4.7 (including) | 0.4.7 (including) |
| Cobbler | Michael_dehaan | 0.4.8 (including) | 0.4.8 (including) |
| Cobbler | Michael_dehaan | 0.5.0 (including) | 0.5.0 (including) |
| Cobbler | Michael_dehaan | 0.6.0 (including) | 0.6.0 (including) |
| Cobbler | Michael_dehaan | 0.6.1 (including) | 0.6.1 (including) |
| Cobbler | Michael_dehaan | 0.6.3 (including) | 0.6.3 (including) |
| Cobbler | Michael_dehaan | 0.6.4 (including) | 0.6.4 (including) |
| Cobbler | Michael_dehaan | 0.6.5 (including) | 0.6.5 (including) |
| Cobbler | Michael_dehaan | 0.8.1 (including) | 0.8.1 (including) |
| Cobbler | Michael_dehaan | 0.8.3 (including) | 0.8.3 (including) |
| Cobbler | Michael_dehaan | 1.0.0 (including) | 1.0.0 (including) |
| Cobbler | Michael_dehaan | 1.0.2 (including) | 1.0.2 (including) |
| Cobbler | Michael_dehaan | 1.0.2-1 (including) | 1.0.2-1 (including) |
| Cobbler | Michael_dehaan | 1.0.3-1 (including) | 1.0.3-1 (including) |
| Cobbler | Michael_dehaan | 1.2.0 (including) | 1.2.0 (including) |
| Cobbler | Michael_dehaan | 1.2.2 (including) | 1.2.2 (including) |
| Cobbler | Michael_dehaan | 1.2.3 (including) | 1.2.3 (including) |
| Cobbler | Michael_dehaan | 1.2.5 (including) | 1.2.5 (including) |
| Cobbler | Michael_dehaan | 1.2.6 (including) | 1.2.6 (including) |
| Cobbler | Michael_dehaan | 1.2.7 (including) | 1.2.7 (including) |
| Cobbler | Michael_dehaan | 1.2.8 (including) | 1.2.8 (including) |
| Cobbler | Michael_dehaan | 1.2.8-1 (including) | 1.2.8-1 (including) |
| Cobbler | Michael_dehaan | 1.2.9 (including) | 1.2.9 (including) |
| Cobbler | Michael_dehaan | 1.2.9-1 (including) | 1.2.9-1 (including) |
| Cobbler | Michael_dehaan | 1.3.1 (including) | 1.3.1 (including) |
| Cobbler | Michael_dehaan | 1.3.1-1 (including) | 1.3.1-1 (including) |
| Cobbler | Michael_dehaan | 1.3.3 (including) | 1.3.3 (including) |
| Cobbler | Michael_dehaan | 1.3.3-1 (including) | 1.3.3-1 (including) |
| Cobbler | Michael_dehaan | 1.3.4 (including) | 1.3.4 (including) |
| Cobbler | Michael_dehaan | 1.3.4-1 (including) | 1.3.4-1 (including) |
| Cobbler | Michael_dehaan | 1.4.0 (including) | 1.4.0 (including) |
| Cobbler | Michael_dehaan | 1.4.0-2 (including) | 1.4.0-2 (including) |
| Cobbler | Michael_dehaan | 1.4.1 (including) | 1.4.1 (including) |
| Cobbler | Michael_dehaan | 1.4.1-1 (including) | 1.4.1-1 (including) |
| Cobbler | Michael_dehaan | 1.4.2 (including) | 1.4.2 (including) |
| Cobbler | Michael_dehaan | 1.4.2-1 (including) | 1.4.2-1 (including) |
| Cobbler | Michael_dehaan | 1.4.3 (including) | 1.4.3 (including) |
| Cobbler | Michael_dehaan | 1.4.3-4 (including) | 1.4.3-4 (including) |
| Cobbler | Michael_dehaan | 1.6.1 (including) | 1.6.1 (including) |
| Cobbler | Michael_dehaan | 1.6.1-1 (including) | 1.6.1-1 (including) |
| Cobbler | Michael_dehaan | 1.6.2 (including) | 1.6.2 (including) |
| Cobbler | Michael_dehaan | 1.6.2-1 (including) | 1.6.2-1 (including) |
| Cobbler | Michael_dehaan | 1.6.3 (including) | 1.6.3 (including) |
| Cobbler | Michael_dehaan | 1.6.3-1 (including) | 1.6.3-1 (including) |
| Cobbler | Michael_dehaan | 1.6.4 (including) | 1.6.4 (including) |
| Cobbler | Michael_dehaan | 1.6.4-1 (including) | 1.6.4-1 (including) |
| Cobbler | Michael_dehaan | 1.6.5 (including) | 1.6.5 (including) |
| Cobbler | Michael_dehaan | 1.6.5-1 (including) | 1.6.5-1 (including) |
| Cobbler | Michael_dehaan | 1.6.6 (including) | 1.6.6 (including) |
| Cobbler | Michael_dehaan | 1.6.6-1 (including) | 1.6.6-1 (including) |
| Cobbler | Michael_dehaan | 1.6.8 (including) | 1.6.8 (including) |
| Cobbler | Michael_dehaan | 1.6.8-1 (including) | 1.6.8-1 (including) |
| Cobbler | Michael_dehaan | 2.0.0 (including) | 2.0.0 (including) |
| Cobbler | Michael_dehaan | 2.0.0-1 (including) | 2.0.0-1 (including) |
| Cobbler | Michael_dehaan | 2.0.1 (including) | 2.0.1 (including) |
| Cobbler | Michael_dehaan | 2.0.1-1 (including) | 2.0.1-1 (including) |
| Cobbler | Michael_dehaan | 2.0.3 (including) | 2.0.3 (including) |
| Cobbler | Michael_dehaan | 2.0.3.1 (including) | 2.0.3.1 (including) |
| Cobbler | Michael_dehaan | 2.0.3.1-2 (including) | 2.0.3.1-2 (including) |
| Cobbler | Michael_dehaan | 2.0.4-1 (including) | 2.0.4-1 (including) |
| Red Hat Network Satellite Server v 5.3 | RedHat | cobbler-0:1.6.6-15.el4sat | * |