EyeOS User And Password Information Disclosure Vulnerability
BID:15256
Info
EyeOS User And Password Information Disclosure Vulnerability
| Bugtraq ID: | 15256 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2005 12:00AM |
| Updated: | Nov 01 2005 12:00AM |
| Credit: | Ryan McGeehan is credited with the discovery of this vulnerability. |
| Vulnerable: |
eyeOS eyeOS 0.8.4 -r1 eyeOS eyeOS 0.8.4 eyeOS eyeOS 0.8.3 -r2 eyeOS eyeOS 0.8.3 |
| Not Vulnerable: |
eyeOS eyeOS 0.8.5 |
Discussion
EyeOS User And Password Information Disclosure Vulnerability
eyeOS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.
An attacker can exploit this vulnerability to obtain a list of valid usernames and their corresponding encrypted passwords. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
eyeOS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.
An attacker can exploit this vulnerability to obtain a list of valid usernames and their corresponding encrypted passwords. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
EyeOS User And Password Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
EyeOS User And Password Information Disclosure Vulnerability
Solution:
The vendor has addressed this issue eyeOS version 0.8.5. Users are advised to consult the security manual enclosed with the vendor upgrade.
eyeOS eyeOS 0.8.3
eyeOS eyeOS 0.8.3 -r2
eyeOS eyeOS 0.8.4 -r1
eyeOS eyeOS 0.8.4
Solution:
The vendor has addressed this issue eyeOS version 0.8.5. Users are advised to consult the security manual enclosed with the vendor upgrade.
eyeOS eyeOS 0.8.3
-
eyeOS eyeOS-0.8.5-r1.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.5-r1.tar.gz?downloa d
eyeOS eyeOS 0.8.3 -r2
-
eyeOS eyeOS-0.8.5-r1.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.5-r1.tar.gz?downloa d
eyeOS eyeOS 0.8.4 -r1
-
eyeOS eyeOS-0.8.5-r1.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.5-r1.tar.gz?downloa d
eyeOS eyeOS 0.8.4
-
eyeOS eyeOS-0.8.5-r1.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.5-r1.tar.gz?downloa d
References
EyeOS User And Password Information Disclosure Vulnerability
References:
References:
- eyeOS 0.8.4 Multiple Vulnerabilities (Ryan McGeehan)
- eyeOS Homepage (eyeOS)