Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37715
Info
Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37715 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4489 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | Jan 12 2010 03:21AM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
Cherokee-Project Cherokee HTTPD 0.99.30 |
| Not Vulnerable: |
Cherokee-Project Cherokee HTTPD 0.99.34 |
Discussion
Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
Cherokee is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Cherokee 0.99.30 and prior are vulnerable.
Cherokee is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Cherokee 0.99.30 and prior are vulnerable.
Exploit / POC
Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
Solution / Fix
Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Cherokee-Project Cherokee HTTPD 0.99.30
Solution:
Updates are available. Please see the references for details.
Cherokee-Project Cherokee HTTPD 0.99.30
-
Cherokee cherokee-0.99.34.tar.gz
http://www.cherokee-project.com/download/0.99/0.99.34/cherokee-0.99.34 .tar.gz
References
Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: