Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
BID:38395
Info
Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
| Bugtraq ID: | 38395 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2010 12:00AM |
| Updated: | Feb 24 2010 12:00AM |
| Credit: | Nicob |
| Vulnerable: |
Kojoney Kojoney (SSH honeypot) 0.0.4.1 |
| Not Vulnerable: |
Kojoney Kojoney (SSH honeypot) 0.0.4.2 |
Discussion
Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
Kojoney is prone to a remote denial-of-service vulnerability.
A remote attacker can exploit this issue to gain unauthorized access to local files and crash the affected application, resulting in a denial-of-service condition.
Versions prior to Kojoney 0.0.4.2 are vulnerable.
Kojoney is prone to a remote denial-of-service vulnerability.
A remote attacker can exploit this issue to gain unauthorized access to local files and crash the affected application, resulting in a denial-of-service condition.
Versions prior to Kojoney 0.0.4.2 are vulnerable.
Exploit / POC
Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
An attacker can use readability available network utilities to exploit this issue.
The following example URI is available:
file://localhost/dev/urandom
An attacker can use readability available network utilities to exploit this issue.
The following example URI is available:
file://localhost/dev/urandom
Solution / Fix
Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Kojoney Kojoney (SSH honeypot) 0.0.4.1
Solution:
Updates are available. Please see the references for details.
Kojoney Kojoney (SSH honeypot) 0.0.4.1
-
Kojoney kojoney-0.0.4.2.tar.gz
http://sourceforge.net/projects/kojoney/files/kojoney-0.0.4.2.tar.gz/d ownload
References
Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
References:
References:
- Kojoney Homepage (Kojoney)
- Kojoney (SSH honeypot) remote DoS (Nicob
)