LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
BID:28577
Info
LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
| Bugtraq ID: | 28577 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6195 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
LANDesk Software LANDesk Management Suite 8.80.1 .1 |
| Not Vulnerable: | |
Discussion
LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
LANDesk Management Suite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP application's root directory. This can expose sensitive information that could help the attacker launch further attacks.
LANDesk Management Suite 8.80.1.1 is vulnerable; other versions may also be affected.
LANDesk Management Suite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP application's root directory. This can expose sensitive information that could help the attacker launch further attacks.
LANDesk Management Suite 8.80.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LANDesk Management Suite 8.80.1.1 PXE TFTP Service Directory Traversal Vulnerability
References:
References:
- Vendor Homepage (LANDesk Software)
- Directory traversal in LANDesk Management Suite 8.80.1.1 (Luigi Auriemma
)