FIDOGATE Logfile Path Input Validation Vulnerability
BID:11005
Info
FIDOGATE Logfile Path Input Validation Vulnerability
| Bugtraq ID: | 11005 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Aug 23 2004 12:00AM |
| Credit: | Discovery is credited to Niels Heinen. |
| Vulnerable: |
FIDOGATE FIDOGATE 4.4.9 FIDOGATE FIDOGATE 4.4.7 FIDOGATE FIDOGATE 4.4.6 FIDOGATE FIDOGATE 4.4.5 |
| Not Vulnerable: |
FIDOGATE FIDOGATE 4.4.10 |
Discussion
FIDOGATE Logfile Path Input Validation Vulnerability
FIDOGATE is prone to an input validation error that may permit local users to append to or create files with the privileges of the program. The source of the problem is that the attacker may control the location of the logfile. Since the program is typically setuid 'news', this could be exploited to append to or create files in the context of that user.
This issue would only affect versions of the software for UNIX/Linux variants.
FIDOGATE is prone to an input validation error that may permit local users to append to or create files with the privileges of the program. The source of the problem is that the attacker may control the location of the logfile. Since the program is typically setuid 'news', this could be exploited to append to or create files in the context of that user.
This issue would only affect versions of the software for UNIX/Linux variants.
Exploit / POC
FIDOGATE Logfile Path Input Validation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
FIDOGATE Logfile Path Input Validation Vulnerability
Solution:
This issue has been addressed in FIDOGATE version 4.4.10. Users are advised to upgrade at the first possible opportunity.
FIDOGATE FIDOGATE 4.4.5
FIDOGATE FIDOGATE 4.4.6
FIDOGATE FIDOGATE 4.4.7
FIDOGATE FIDOGATE 4.4.9
Solution:
This issue has been addressed in FIDOGATE version 4.4.10. Users are advised to upgrade at the first possible opportunity.
FIDOGATE FIDOGATE 4.4.5
FIDOGATE FIDOGATE 4.4.6
FIDOGATE FIDOGATE 4.4.7
FIDOGATE FIDOGATE 4.4.9
References
FIDOGATE Logfile Path Input Validation Vulnerability
References:
References:
- ChangeLog (FIDOGATE)
- FIDOGATE CVS (FIDOGATE)
- FIDOGATE Homepage (FIDOGATE)