Netjuke Remote Command Execution Vulnerability
BID:3988
Info
Netjuke Remote Command Execution Vulnerability
| Bugtraq ID: | 3988 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2002 12:00AM |
| Updated: | Jan 26 2002 12:00AM |
| Credit: | Published in a Netjuke changelog. |
| Vulnerable: |
Netjuke Netjuke 1.0 b6 Netjuke Netjuke 1.0 b5 Netjuke Netjuke 1.0 b4 Netjuke Netjuke 1.0 b3 Netjuke Netjuke 1.0 b2 Netjuke Netjuke 1.0 b1 |
| Not Vulnerable: |
Netjuke Netjuke 1.0 b7 |
Discussion
Netjuke Remote Command Execution Vulnerability
Netjuke is a web based audio streaming jukebox program which supports MP3, Ogg Vorbis, and other music file formats.
An issue exists in versions of Netjuke prior to 1.0b7 which could enable remote attackers to execute arbitrary commands as the web server user. Exploitation of this issue could lead to a compromise of the host.
This issue is the result of insufficient validation of user input passed to the 'section' variable.
Netjuke is a web based audio streaming jukebox program which supports MP3, Ogg Vorbis, and other music file formats.
An issue exists in versions of Netjuke prior to 1.0b7 which could enable remote attackers to execute arbitrary commands as the web server user. Exploitation of this issue could lead to a compromise of the host.
This issue is the result of insufficient validation of user input passed to the 'section' variable.
Exploit / POC
Netjuke Remote Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Netjuke Remote Command Execution Vulnerability
Solution:
Netjuke has released 1.0b6.2 patch for versions 1.0 b3 through b6 which will address this issue. However, it is recommended to upgrade to 1.0b7 which also addresses this issue:
Netjuke Netjuke 1.0 b6
Netjuke Netjuke 1.0 b1
Netjuke Netjuke 1.0 b4
Netjuke Netjuke 1.0 b2
Netjuke Netjuke 1.0 b3
Netjuke Netjuke 1.0 b5
Solution:
Netjuke has released 1.0b6.2 patch for versions 1.0 b3 through b6 which will address this issue. However, it is recommended to upgrade to 1.0b7 which also addresses this issue:
Netjuke Netjuke 1.0 b6
-
Netjuke netjuke-patches-1.0b6.2
http://sourceforge.net/tracker/download.php?group_id=42076&atid=432052 &file_id=16607&aid=507312 -
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
Netjuke Netjuke 1.0 b1
-
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
Netjuke Netjuke 1.0 b4
-
Netjuke netjuke-patches-1.0b6.2
http://sourceforge.net/tracker/download.php?group_id=42076&atid=432052 &file_id=16607&aid=507312 -
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
Netjuke Netjuke 1.0 b2
-
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
Netjuke Netjuke 1.0 b3
-
Netjuke netjuke-patches-1.0b6.2
http://sourceforge.net/tracker/download.php?group_id=42076&atid=432052 &file_id=16607&aid=507312 -
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
Netjuke Netjuke 1.0 b5
-
Netjuke netjuke-patches-1.0b6.2
http://sourceforge.net/tracker/download.php?group_id=42076&atid=432052 &file_id=16607&aid=507312 -
Netjuke netjuke-1.0b7
http://prdownloads.sourceforge.net/netjuke/netjuke-1.0b7.tar.gz
References
Netjuke Remote Command Execution Vulnerability
References:
References:
- Netjuke Homepage (Artekopia)
- Netjuke patch information (Artekopia)