Perforce Multiple Remote Security Vulnerabilities
BID:36261
Info
Perforce Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 36261 |
| Class: | Unknown |
| CVE: |
CVE-2010-0932 CVE-2010-0934 CVE-2010-0935 CVE-2010-0930 CVE-2010-0929 CVE-2010-0931 CVE-2010-0933 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Apr 13 2015 08:02PM |
| Credit: | Intevydis |
| Vulnerable: |
Perforce Software Perforce Server 2008.1/160022 |
| Not Vulnerable: | |
Discussion
Perforce Multiple Remote Security Vulnerabilities
Perforce Server is prone to multiple remote security vulnerabilities, including:
- Multiple denial-of-service vulnerabilities
- A directory-traversal vulnerability
- A remote code-execution vulnerability
An attacker can exploit these issues to crash the affected application, execute arbitrary code within the context of the application, or overwrite arbitrary files within the context of the server. Other attacks are also possible.
Perforce 2008.1/160022 is vulnerable; other versions may also be affected.
Perforce Server is prone to multiple remote security vulnerabilities, including:
- Multiple denial-of-service vulnerabilities
- A directory-traversal vulnerability
- A remote code-execution vulnerability
An attacker can exploit these issues to crash the affected application, execute arbitrary code within the context of the application, or overwrite arbitrary files within the context of the server. Other attacks are also possible.
Perforce 2008.1/160022 is vulnerable; other versions may also be affected.
Exploit / POC
Perforce Multiple Remote Security Vulnerabilities
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Perforce Multiple Remote Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Perforce Multiple Remote Security Vulnerabilities
References:
References:
- [Dailydave] Perforce (Intevydis)
- Perforce Server Homepage (Perforce Software)
- VulnDisco Pack Professional (Intevydis)