Chesapeake TFTP Server Remote Directory Traversal Vulnerability
BID:11582
Info
Chesapeake TFTP Server Remote Directory Traversal Vulnerability
| Bugtraq ID: | 11582 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2004 12:00AM |
| Updated: | Oct 30 2004 12:00AM |
| Credit: | Discovery is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Chesapeake TFTP Server 1.0 |
| Not Vulnerable: | |
Discussion
Chesapeake TFTP Server Remote Directory Traversal Vulnerability
Chesapeake TFTP Server is reported susceptible to a directory traversal vulnerability. This vulnerability allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the TFTP server process.
Chesapeake TFTP Server version 1.0 is reported prone to this issue.
Chesapeake TFTP Server is reported susceptible to a directory traversal vulnerability. This vulnerability allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the TFTP server process.
Chesapeake TFTP Server version 1.0 is reported prone to this issue.
Exploit / POC
Chesapeake TFTP Server Remote Directory Traversal Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://aluigi.altervista.org/testz/tftpx.zip
An exploit is not required.
A proof of concept is available from the following location:
http://aluigi.altervista.org/testz/tftpx.zip
Solution / Fix
Chesapeake TFTP Server Remote Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Chesapeake TFTP Server Remote Directory Traversal Vulnerability
References:
References:
- Chesapeake TFTP Server (Luigi Auriemma)
- TFTP Server Product Page (Netcordia)