MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
BID:25093
Info
MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
| Bugtraq ID: | 25093 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2007 12:00AM |
| Updated: | Jul 30 2007 05:45PM |
| Credit: | blupp discovered this issue. |
| Vulnerable: |
Mldonkey Mldonkey 2.8 Mldonkey Mldonkey 2.7 Mldonkey Mldonkey 2.6 Mldonkey Mldonkey 2.5 -4 Mldonkey Mldonkey 2.5 |
| Not Vulnerable: |
Mldonkey Mldonkey 2.9 |
Discussion
MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
MLDonkey is prone to a security-bypass vulnerability due to a design error.
Users who enable country-based IP-blocking may have a false sense of security.
Attackers can exploit this issue to temporarily connect to the application using supposedly blocked IP addresses.
Versions prior to MLDonkey 2.9.0 are vulnerable.
MLDonkey is prone to a security-bypass vulnerability due to a design error.
Users who enable country-based IP-blocking may have a false sense of security.
Attackers can exploit this issue to temporarily connect to the application using supposedly blocked IP addresses.
Versions prior to MLDonkey 2.9.0 are vulnerable.
Exploit / POC
MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
An attacker can exploit this issue using the client application.
An attacker can exploit this issue using the client application.
Solution / Fix
MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Mldonkey Mldonkey 2.5 -4
Mldonkey Mldonkey 2.5
Mldonkey Mldonkey 2.6
Mldonkey Mldonkey 2.7
Mldonkey Mldonkey 2.8
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Mldonkey Mldonkey 2.5 -4
-
Mldonkey mldonkey-2.9.0.tar.bz2
http://downloads.sourceforge.net/mldonkey/mldonkey-2.9.0.tar.bz2?modti me=1185537552&big_mirror=0
Mldonkey Mldonkey 2.5
-
Mldonkey mldonkey-2.9.0.tar.bz2
http://downloads.sourceforge.net/mldonkey/mldonkey-2.9.0.tar.bz2?modti me=1185537552&big_mirror=0
Mldonkey Mldonkey 2.6
-
Mldonkey mldonkey-2.9.0.tar.bz2
http://downloads.sourceforge.net/mldonkey/mldonkey-2.9.0.tar.bz2?modti me=1185537552&big_mirror=0
Mldonkey Mldonkey 2.7
-
Mldonkey mldonkey-2.9.0.tar.bz2
http://downloads.sourceforge.net/mldonkey/mldonkey-2.9.0.tar.bz2?modti me=1185537552&big_mirror=0
Mldonkey Mldonkey 2.8
-
Mldonkey mldonkey-2.9.0.tar.bz2
http://downloads.sourceforge.net/mldonkey/mldonkey-2.9.0.tar.bz2?modti me=1185537552&big_mirror=0
References
MLDonkey Country-Based IP Blocking Security Bypass Vulnerability
References:
References:
- ip_blocking_countries broken? (MLDonkey)
- MLDonkey Homepage (MLDonkey)