'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
BID:27182
Info
'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 27182 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6610 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2007 12:00AM |
| Updated: | Jan 10 2008 07:49PM |
| Credit: | Erich Schubert is credited with the discovery of this issue. |
| Vulnerable: |
unp unp 1.0.12 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha |
| Not Vulnerable: |
unp unp 1.0.14 unp unp 1.0.13 |
Discussion
'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
The 'unp' package is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the application using the vulnerable version of 'unp'. This may facilitate the remote compromise of affected computers.
This issue affects unp 1.0.12; other versions may also be affected.
The 'unp' package is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the application using the vulnerable version of 'unp'. This may facilitate the remote compromise of affected computers.
This issue affects unp 1.0.12; other versions may also be affected.
Exploit / POC
'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
References
'unp' File Name Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- #448437 unp: Incomplete filename escaping (Erich Schubert)