BSCW Symbolic Link File Disclosure Vulnerability
BID:3227
Info
BSCW Symbolic Link File Disclosure Vulnerability
| Bugtraq ID: | 3227 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2001 12:00AM |
| Updated: | Aug 23 2001 12:00AM |
| Credit: | Reported to Bugtraq by neoavatar <[email protected]> on August 23, 2001. |
| Vulnerable: |
GMD FIT BSCW 3.4.3 GMD FIT BSCW 3.4.2 GMD FIT BSCW 3.4.1 GMD FIT BSCW 3.4 GMD FIT BSCW 3.3 GMD FIT BSCW 3.2 GMD FIT BSCW 3.1 GMD FIT BSCW 3.0 |
| Not Vulnerable: | |
Discussion
BSCW Symbolic Link File Disclosure Vulnerability
BSCW (Basic Support for Cooperative Work) enables collaboration over the Web. BSCW is a 'shared workspace' system which supports document upload, event notification, group management and much more.
A vulnerability exists in BSCW that may allow users to view arbitrary files on a system. When users view extracted files in their "data-bag", BSCW will follow symbolic links.
A malicious user may be able to exploit this problem to view any file on a system accessible by the user id under which BSCW runs.
BSCW (Basic Support for Cooperative Work) enables collaboration over the Web. BSCW is a 'shared workspace' system which supports document upload, event notification, group management and much more.
A vulnerability exists in BSCW that may allow users to view arbitrary files on a system. When users view extracted files in their "data-bag", BSCW will follow symbolic links.
A malicious user may be able to exploit this problem to view any file on a system accessible by the user id under which BSCW runs.
Exploit / POC
BSCW Symbolic Link File Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BSCW Symbolic Link File Disclosure Vulnerability
References:
References:
- BSCW Homepage (GMD FIT)
- OrbiTeam Software Homepage (OrbiTeam Software GmbH)