Ginp Java Preferences API Access Control Bypass Vulnerability
BID:12386
Info
Ginp Java Preferences API Access Control Bypass Vulnerability
| Bugtraq ID: | 12386 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2005 12:00AM |
| Updated: | Jan 27 2005 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
ginp ginp 0.20 ginp ginp 0.17 ginp ginp 0.16 ginp ginp 0.15 ginp ginp 0.14 ginp ginp 0.13 ginp ginp 0.12 ginp ginp 0.11 ginp ginp 0.10 |
| Not Vulnerable: |
ginp ginp 0.21 |
Discussion
Ginp Java Preferences API Access Control Bypass Vulnerability
ginp is reported prone to a remote access control bypass vulnerability. Reports indicate that in some cases preferences are not correctly saved, leading to an issue where users may gain access to images that are supposed to be restricted.
It is reported that this vulnerability affects ginp version 0.20, previous versions may also be affected.
ginp is reported prone to a remote access control bypass vulnerability. Reports indicate that in some cases preferences are not correctly saved, leading to an issue where users may gain access to images that are supposed to be restricted.
It is reported that this vulnerability affects ginp version 0.20, previous versions may also be affected.
Exploit / POC
Ginp Java Preferences API Access Control Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Ginp Java Preferences API Access Control Bypass Vulnerability
Solution:
The vendor has released a fix to address this vulnerability:
ginp ginp 0.10
ginp ginp 0.11
ginp ginp 0.12
ginp ginp 0.13
ginp ginp 0.14
ginp ginp 0.15
ginp ginp 0.16
ginp ginp 0.17
ginp ginp 0.20
Solution:
The vendor has released a fix to address this vulnerability:
ginp ginp 0.10
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.11
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.12
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.13
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.14
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.15
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.16
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.17
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663
ginp ginp 0.20
-
ginp ginp-src-v0.21.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=105663