ht://Dig Remote Denial of Service/File Disclosure Vulnerability

BID:3410

Info

ht://Dig Remote Denial of Service/File Disclosure Vulnerability

Bugtraq ID: 3410
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Oct 07 2001 12:00AM
Updated: Oct 07 2001 12:00AM
Credit: This vulnerability was submitted to BugTraq on October 7th, 2001 by Geoff Hutchison <[email protected]>.
Vulnerable: The ht://Dig Group ht://Dig 3.2 0b3
- Debian Linux 2.1
- Debian Linux 2.0
- HP HP-UX 10.20
- HP HP-UX 9.10
+ HP Secure OS software for Linux 1.0
+ Redhat Linux 7.2
+ Redhat Linux 7.1
- Sun Solaris 2.6
- Sun Solaris 2.5
- Sun SunOS 4.1.4
The ht://Dig Group ht://Dig 3.2 0b2
- Debian Linux 2.1
- Debian Linux 2.0
- HP HP-UX 10.20
- HP HP-UX 9.10
- Sun Solaris 2.6
- Sun Solaris 2.5
- Sun SunOS 4.1.4
The ht://Dig Group ht://Dig 3.2 .0
+ Mandriva Linux Mandrake 8.1
The ht://Dig Group ht://Dig 3.1.5 -7
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1
The ht://Dig Group ht://Dig 3.1.5
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
- Debian Linux 2.1
- Debian Linux 2.0
- HP HP-UX 10.20
- HP HP-UX 9.10
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
- Sun Solaris 2.6
- Sun Solaris 2.5
- Sun SunOS 4.1.4
Not Vulnerable: The ht://Dig Group ht://Dig 3.2 0b4
- Debian Linux 2.1
- Debian Linux 2.0
- HP HP-UX 10.20
- HP HP-UX 9.10
- Sun Solaris 2.6
- Sun Solaris 2.5
- Sun SunOS 4.1.4
The ht://Dig Group ht://Dig 3.1.6
+ Debian Linux 3.0
- Debian Linux 2.1
- Debian Linux 2.0
+ Gentoo Linux
- HP HP-UX 10.20
- HP HP-UX 9.10
- Sun Solaris 2.6
- Sun Solaris 2.5
- Sun SunOS 4.1.4
The ht://Dig Group ht://Dig 3.1.5 -8
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1

Discussion

ht://Dig Remote Denial of Service/File Disclosure Vulnerability

ht://Dig is freely available, open-source web search engine and indexing software.

ht://Dig is usable via the web interface or from the command line. It may be possible for a remote attacker to cause a denial of service or under certain circumstances display arbitrary web-readable files. This is due to the fact that it is possible to use command line arguments from the web interface. In particular, the -c [filename] argument is normally used to specify an alternate configuration file. Using the web interface to request /dev/zero may cause a denial of service by exhausting resources on the host. A request for a web-readable file may cause it to be disclosed.

Sensitive information contained in disclosed web-readable files may be used to mount further attacks on the host.

Exploit / POC

ht://Dig Remote Denial of Service/File Disclosure Vulnerability

This issue may be exploited with a web browser.

Solution / Fix

ht://Dig Remote Denial of Service/File Disclosure Vulnerability

Solution:
It is recommended by Hewlett-Packard Company that customers download the RPMs listed in the following Red Hat Security Advisory:

2002-03-12 RHSA-2001:139 Updated htdig packages are available

http://rhn.redhat.com/errata/RHSA-2001-139.html

Upgrades available.


The ht://Dig Group ht://Dig 3.1.5 -7

The ht://Dig Group ht://Dig 3.1.5

The ht://Dig Group ht://Dig 3.2 0b3

The ht://Dig Group ht://Dig 3.2 .0

The ht://Dig Group ht://Dig 3.2 0b2

References

ht://Dig Remote Denial of Service/File Disclosure Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report