LANDesk Management Suite TFTP service Directory Traversal Vulnerability
BID:28535
Info
LANDesk Management Suite TFTP service Directory Traversal Vulnerability
| Bugtraq ID: | 28535 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1643 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2008 12:00AM |
| Updated: | May 07 2015 05:31PM |
| Credit: | Parvez Anwar |
| Vulnerable: |
LANDesk Software LANDesk Management Suite 8.8 LANDesk Software LANDesk Management Suite 8.7 SP5 |
| Not Vulnerable: | |
Discussion
LANDesk Management Suite TFTP service Directory Traversal Vulnerability
LANDesk Management Suite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP application's root directory. This can expose sensitive information that could help the attacker launch further attacks.
LANDesk Management Suite 8.8 as well as 8.7 SP5 and prior service packs are vulnerable.
LANDesk Management Suite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP application's root directory. This can expose sensitive information that could help the attacker launch further attacks.
LANDesk Management Suite 8.8 as well as 8.7 SP5 and prior service packs are vulnerable.
Exploit / POC
LANDesk Management Suite TFTP service Directory Traversal Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
LANDesk Management Suite TFTP service Directory Traversal Vulnerability
Solution:
The vendor has released patches. Please see the references for more information.
LANDesk Software LANDesk Management Suite 8.8
LANDesk Software LANDesk Management Suite 8.7 SP5
Solution:
The vendor has released patches. Please see the references for more information.
LANDesk Software LANDesk Management Suite 8.8
-
LANDesk Software OSD-737488.0.zip
http://community.landesk.com/support/servlet/JiveServlet/download/2659 -1-1781/OSD-737488.0.zip
LANDesk Software LANDesk Management Suite 8.7 SP5
-
LANDesk Software OSD-737487.5.zip
http://community.landesk.com/support/servlet/JiveServlet/download/2659 -1-1780/OSD-737487.5.zip
References
LANDesk Management Suite TFTP service Directory Traversal Vulnerability
References:
References:
- Vendor Homepage (LANDesk Software)
- LANDesk Security Bulletin �?? TFTP access through directory traversal on LANDesk P (LANDesk Software)