Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
BID:13682
Info
Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
| Bugtraq ID: | 13682 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | This issue was reported by US-CERT. |
| Vulnerable: |
Groove Networks Workspace 2.5 Groove Networks Workspace 2.0 Groove Networks Virtual Office 3.1 a Groove Networks Virtual Office 3.1 Groove Networks Virtual Office 3.0 |
| Not Vulnerable: |
Groove Networks Workspace 2.5 n build 1871 Groove Networks Virtual Office 3.1 build 2338 Groove Networks Virtual Office 3.1 a build 2364 |
Discussion
Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
Groove Virtual Office is affected by a vulnerability that allows remote attackers to obfuscate file extensions of potentially malicious files.
The file extension of a specially crafted file may be obfuscated in a manner that creates a false sense of security for a user.
The user may be inclined to open a malicious file that could lead to arbitrary code execution. This may allow an attacker to gain unauthorized access to a computer in the context of the vulnerable user.
Groove Virtual Office is affected by a vulnerability that allows remote attackers to obfuscate file extensions of potentially malicious files.
The file extension of a specially crafted file may be obfuscated in a manner that creates a false sense of security for a user.
The user may be inclined to open a malicious file that could lead to arbitrary code execution. This may allow an attacker to gain unauthorized access to a computer in the context of the vulnerable user.
Exploit / POC
Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
References
Groove Networks Groove Virtual Office File Extension Obfuscation Vulnerability
References:
References:
- Home Page (Groove Networks)
- Vulnerability Note VU#232232 - Groove Virtual Office may not correctly (CERT)