Unrated severityNVD Advisory· Published Jul 3, 2012· Updated Apr 29, 2026
CVE-2012-3366
CVE-2012-3366
Description
The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).
Affected products
2Patches
1a524967e8d5chttps://github.com/Bcfg2/bcfg2via nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
7- github.com/Bcfg2/bcfg2/commit/a524967e8d5c4c22e49cd619aed20c87a316c0benvdPatch
- secunia.com/advisories/49629nvdVendor Advisory
- secunia.com/advisories/49690nvdVendor Advisory
- permalink.gmane.org/gmane.comp.sysutils.bcfg2.devel/4539nvd
- www.debian.org/security/2012/dsa-2503nvd
- www.securityfocus.com/bid/54217nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/76616nvd
News mentions
0No linked articles in our index yet.