ZHCon Unauthorized File Disclosure Vulnerability
BID:12343
Info
ZHCon Unauthorized File Disclosure Vulnerability
| Bugtraq ID: | 12343 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-0072 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 24 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery of this vulnerability is credited to Erik Sjolund. |
| Vulnerable: |
zhcon zhcon 0.2.3 zhcon zhcon 0.2.2 zhcon zhcon 0.2.1 zhcon zhcon 0.2 |
| Not Vulnerable: | |
Discussion
ZHCon Unauthorized File Disclosure Vulnerability
zhcon is reportedly affected by a vulnerability allowing reading of arbitrary files with escalated privileges. This could permit an unauthorized user to read arbitrary files owned by other users without authorization. Disclosure of sensitive information may lead to a system compromise, or aid in other attacks.
This issue is reported to affect zhcon version 0.2.3; earlier versions may also be affected.
zhcon is reportedly affected by a vulnerability allowing reading of arbitrary files with escalated privileges. This could permit an unauthorized user to read arbitrary files owned by other users without authorization. Disclosure of sensitive information may lead to a system compromise, or aid in other attacks.
This issue is reported to affect zhcon version 0.2.3; earlier versions may also be affected.
Exploit / POC
ZHCon Unauthorized File Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ZHCon Unauthorized File Disclosure Vulnerability
Solution:
Mandrake has released MDKSA-2005:012 addressing this issue. Please see the referenced advisory for more information.
Debian Linux has released advisory DSA 655-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
zhcon zhcon 0.2
zhcon zhcon 0.2.3
Solution:
Mandrake has released MDKSA-2005:012 addressing this issue. Please see the referenced advisory for more information.
Debian Linux has released advisory DSA 655-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
zhcon zhcon 0.2
-
Debian zhcon_0.2-4woody3_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _alpha.deb -
Debian zhcon_0.2-4woody3_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _arm.deb -
Debian zhcon_0.2-4woody3_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _hppa.deb -
Debian zhcon_0.2-4woody3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _i386.deb -
Debian zhcon_0.2-4woody3_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _ia64.deb -
Debian zhcon_0.2-4woody3_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _m68k.deb -
Debian zhcon_0.2-4woody3_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _mips.deb -
Debian zhcon_0.2-4woody3_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _mipsel.deb -
Debian zhcon_0.2-4woody3_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _powerpc.deb -
Debian zhcon_0.2-4woody3_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _s390.deb -
Debian zhcon_0.2-4woody3_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zhcon/zhcon_0.2-4woody3 _sparc.deb
zhcon zhcon 0.2.3
-
Mandrake zhcon-0.2.3-6.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake zhcon-0.2.3-6.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake zhcon-0.2.3-6.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake zhcon-0.2.3-6.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php