Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 13.04 | 13.04.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / maas | 12.04.1 | 12.04.1.x |
| canonical / maas | 12.04.3 | 12.04.3.x |
| canonical / maas | - | 12.04.4.x |
| canonical / maas | 12.04.2 | 12.04.2.x |