Perforce Server User Workspace Directory Traversal Vulnerability
BID:38586
Info
Perforce Server User Workspace Directory Traversal Vulnerability
| Bugtraq ID: | 38586 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2010 12:00AM |
| Updated: | Mar 08 2010 12:00AM |
| Credit: | McAfee |
| Vulnerable: |
Perforce Perforce Server 2009.2 |
| Not Vulnerable: | |
Discussion
Perforce Server User Workspace Directory Traversal Vulnerability
Perforce Server is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to overwrite arbitrary files within the context of the application. Successful exploits may compromise the affected application and possibly the underlying computer.
Perforce Server 2009.2 is vulnerable; other versions may also be affected.
Perforce Server is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to overwrite arbitrary files within the context of the application. Successful exploits may compromise the affected application and possibly the underlying computer.
Perforce Server 2009.2 is vulnerable; other versions may also be affected.
Exploit / POC
Perforce Server User Workspace Directory Traversal Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
Perforce Server User Workspace Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Perforce Server User Workspace Directory Traversal Vulnerability
References:
References:
- Perforce Server Homepage (Perforce Software)
- Protecting Your Critical Assets Lessons Learned from 'Operation Aurora' (McAfee)