Roundup Remote File Disclosure Vulnerability
BID:10495
Info
Roundup Remote File Disclosure Vulnerability
| Bugtraq ID: | 10495 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1444 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to Vickenty Fesunov. |
| Vulnerable: |
Roundup Roundup 0.6.11 Roundup Roundup 0.5.9 Roundup Roundup 0.5.8 Stable Roundup Roundup 0.5.7 Roundup Roundup 0.5.6 Roundup Roundup 0.5.5 Roundup Roundup 0.5.4 Roundup Roundup 0.5.3 Roundup Roundup 0.5.2 Roundup Roundup 0.5.1 Roundup Roundup 0.5 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 |
| Not Vulnerable: |
Roundup Roundup 0.7.3 |
Discussion
Roundup Remote File Disclosure Vulnerability
Roundup is prone to a remote file disclosure vulnerability. A remote user can disclose files on a vulnerable computer by using the /home/@@file/ prefix and '../' directory traversal sequences.
This vulnerability affects Roundup 0.6.11 and prior versions.
Roundup is prone to a remote file disclosure vulnerability. A remote user can disclose files on a vulnerable computer by using the /home/@@file/ prefix and '../' directory traversal sequences.
This vulnerability affects Roundup 0.6.11 and prior versions.
Exploit / POC
Roundup Remote File Disclosure Vulnerability
No exploit is required.
The following proof of concept is available:
GET /cit/@@file/../../../../etc/passwd HTTP/1.0
No exploit is required.
The following proof of concept is available:
GET /cit/@@file/../../../../etc/passwd HTTP/1.0
Solution / Fix
Roundup Remote File Disclosure Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200408-09) to provide updates. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-www/roundup-0.7.6"
emerge ">=net-www/roundup-0.7.6"
Roundup version 0.7.3 is available to address this issue:
Roundup Roundup 0.5
Roundup Roundup 0.5.1
Roundup Roundup 0.5.2
Roundup Roundup 0.5.3
Roundup Roundup 0.5.4
Roundup Roundup 0.5.5
Roundup Roundup 0.5.6
Roundup Roundup 0.5.7
Roundup Roundup 0.5.8 Stable
Roundup Roundup 0.5.9
Roundup Roundup 0.6.11
Solution:
Gentoo has released an advisory (GLSA 200408-09) to provide updates. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-www/roundup-0.7.6"
emerge ">=net-www/roundup-0.7.6"
Roundup version 0.7.3 is available to address this issue:
Roundup Roundup 0.5
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.1
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.2
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.3
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.4
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.5
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.6
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.7
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.8 Stable
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.5.9
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
Roundup Roundup 0.6.11
-
Roundup roundup-0.7.3
http://prdownloads.sourceforge.net/roundup/roundup-0.7.3.tar.gz?downlo ad
References
Roundup Remote File Disclosure Vulnerability
References:
References:
- [ 961511 ] random filesystem access (Roundup)
- Roundup Homepage (Roundup)