FireEye Exploitation: Project Zero’s Vulnerability of the Beast
googleprojectzero.blogspot.com
googleprojectzero.blogspot.com
That said, the manufacturer had configurations to mitigate the damage out within hours and a full patch 2 days after they were notified by Project Zero.
FireEye is a security company. Their business is security and catching hacking attempts. They of all people should know how dangerous it is to scrape and parse potentially malicious data off the wire in large quantities, and yet it doesn't sound like they've taken any special precautions. OK, the JAR disassembler doesn't run as root, but there's a privilege escalation so simple the description fits in a single line of text, so that's not worth much.
The fact that JODE has the potential to execute arbitrary code whilst decompiling isn't a secret, it's mentioned in the FAQ. So there must have been some kind of failure in the development process that led to the appliance developers simply grabbing whatever package they encountered first in order to ship the feature, without taking into account the security of their own software stack.
To me this says that the appliance is very likely to have lots of other vulnerabilities in it. Sort of like how anti-virus engines have been found to be vipers nests of exploits.
does anyone out there know why they're using JODE?
<mirrors>
<mirror>
<id>UK</id>
<name>UK Central</name>
<url>https://repo1.maven.org/maven2</url>
<mirrorOf>central</mirrorOf>
</mirror>
</mirrors>