PatchLink Update Server Arbitrary File Overwrite Vulnerability
BID:18732
CVE-2006-3426 |Info
PatchLink Update Server Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 18732 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2006 12:00AM |
| Updated: | Jun 29 2006 10:24PM |
| Credit: | Chris Steipp of Novacoast is credited with the discovery of this issue. |
| Vulnerable: |
PatchLink PatchLink Update 6.2 .189 PatchLink PatchLink Update 6.2 .181 PatchLink PatchLink Update 6.1 Novell ZENworks Patch Management 6.2 SR1 |
| Not Vulnerable: | |
Discussion
PatchLink Update Server Arbitrary File Overwrite Vulnerability
PatchLink Update Server is prone to a remote file-overwrite vulnerability because the application fails to sanitize user-supplied input before creating files during file transfers.
This issue allows remote attackers to overwrite arbitrary files with arbitrary data. This may aid in further attacks.
PatchLink Update Server is prone to a remote file-overwrite vulnerability because the application fails to sanitize user-supplied input before creating files during file transfers.
This issue allows remote attackers to overwrite arbitrary files with arbitrary data. This may aid in further attacks.
Exploit / POC
PatchLink Update Server Arbitrary File Overwrite Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
PatchLink Update Server Arbitrary File Overwrite Vulnerability
Solution:
The vendor has released fixes to address this issue; please see the reference section for details.
Solution:
The vendor has released fixes to address this issue; please see the reference section for details.
References
PatchLink Update Server Arbitrary File Overwrite Vulnerability
References:
References:
- PatchLink Update (PatchLink)
- PatchLink Update Homepage (Lumension Security)
- Multiple Vulnerabilities in PatchLink Update Server 6 ("Chris Steipp"
)