Comix 'filename' Remote Command Execution Vulnerability
BID:28547
Info
Comix 'filename' Remote Command Execution Vulnerability
| Bugtraq ID: | 28547 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1568 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2008 12:00AM |
| Updated: | Apr 16 2015 05:50PM |
| Credit: | hhaamu |
| Vulnerable: |
Red Hat Fedora 7 Gentoo Linux Comix Comix 3.6.4 |
| Not Vulnerable: | |
Discussion
Comix 'filename' Remote Command Execution Vulnerability
Comix is prone to a remote shell command-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running the affected application.
Comix 3.6.4 is vulnerable; other versions may also be affected.
Comix is prone to a remote shell command-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running the affected application.
Comix 3.6.4 is vulnerable; other versions may also be affected.
Exploit / POC
Comix 'filename' Remote Command Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Comix 'filename' Remote Command Execution Vulnerability
Solution:
The vendor released fixes. Please see the references for more information.
Solution:
The vendor released fixes. Please see the references for more information.
References
Comix 'filename' Remote Command Execution Vulnerability
References:
References: