McAfee ASaP Virusscan Directory Traversal Vulnerability
BID:3020
Info
McAfee ASaP Virusscan Directory Traversal Vulnerability
| Bugtraq ID: | 3020 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2001 12:00AM |
| Updated: | Jul 11 2001 12:00AM |
| Credit: | Reported to Bugtraq by [email protected] on July 11, 2001. |
| Vulnerable: |
McAfee Agent ASaP VirusScan 1.0 |
| Not Vulnerable: | |
Discussion
McAfee ASaP Virusscan Directory Traversal Vulnerability
McAfee AsAP VirusScan is a web-based antivirus service.
The software allows neighbouring PCs on a network to share virus updates. In order to facilitate this service, a "McAfee Agent" process runs on each system, and hosts a small webserver which serves a limited set of files through TCP port 6515.
This webserver is intentionally limited to serving files within \winnt\mycio\agent\rmrcache. However, the service is vulnerable to directory traversal attacks, allowing a remote user to successfully request files from outside this directory scope. By submitting a properly-structured URL incorporating '.../' sequences, a user can ascend from the normally permitted directory tree, and read files from any location on the host filesystem. This could allow an attacker to obtain potentially sensitive or confidential information, which, if properly exploited, could be used to further undermine security on the host.
McAfee AsAP VirusScan is a web-based antivirus service.
The software allows neighbouring PCs on a network to share virus updates. In order to facilitate this service, a "McAfee Agent" process runs on each system, and hosts a small webserver which serves a limited set of files through TCP port 6515.
This webserver is intentionally limited to serving files within \winnt\mycio\agent\rmrcache. However, the service is vulnerable to directory traversal attacks, allowing a remote user to successfully request files from outside this directory scope. By submitting a properly-structured URL incorporating '.../' sequences, a user can ascend from the normally permitted directory tree, and read files from any location on the host filesystem. This could allow an attacker to obtain potentially sensitive or confidential information, which, if properly exploited, could be used to further undermine security on the host.
Solution / Fix
McAfee ASaP Virusscan Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
McAfee ASaP Virusscan Directory Traversal Vulnerability
References:
References: