BadBlue Directory Traversal and Buffer Overflow Vulnerability
BID:26803
Info
BadBlue Directory Traversal and Buffer Overflow Vulnerability
| Bugtraq ID: | 26803 |
| Class: | Unknown |
| CVE: |
CVE-2007-6378 CVE-2007-6379 CVE-2007-6377 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Luigi Auriemma discovered these issues. |
| Vulnerable: |
BadBlue BadBlue 2.72b |
| Not Vulnerable: | |
Discussion
BadBlue Directory Traversal and Buffer Overflow Vulnerability
BadBlue is prone to a directory-traversal vulnerability and a buffer-overflow vulnerability.
An attacker can exploit these issues to upload arbitrary files outside the destination folder (and potentially overwrite existing files), execute arbitrary code within the context of the affected application, or crash the affected application.
BadBlue 2.72b is vulnerable; prior versions may also be affected.
BadBlue is prone to a directory-traversal vulnerability and a buffer-overflow vulnerability.
An attacker can exploit these issues to upload arbitrary files outside the destination folder (and potentially overwrite existing files), execute arbitrary code within the context of the affected application, or crash the affected application.
BadBlue 2.72b is vulnerable; prior versions may also be affected.
Exploit / POC
BadBlue Directory Traversal and Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code and proof-of-concept examples are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code and proof-of-concept examples are available:
Solution / Fix
BadBlue Directory Traversal and Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BadBlue Directory Traversal and Buffer Overflow Vulnerability
References:
References:
- BadBlue Product Page (BadBlue)
- Multiple vulnerabilities in BadBlue 2.72b (Luigi Auriemma
)