Tiny Personal Firewall Locked Terminal Bypass Vulnerability
BID:4207
Info
Tiny Personal Firewall Locked Terminal Bypass Vulnerability
| Bugtraq ID: | 4207 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2002-0349 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 28 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Reported by Andrew Barkley <[email protected]>. |
| Vulnerable: |
Tiny Personal Firewall 2.0.15 |
| Not Vulnerable: | |
Discussion
Tiny Personal Firewall Locked Terminal Bypass Vulnerability
An issue has been reported in Tiny Personal Firewall which could allow a local attacker to permit users unauthorized access to Tiny Personal Firewall. Reportedly, this is possible even if the local system is locked.
Allegedly, a user scanning the network could initiate an alert dialogue in the foreground of a locked workstation with the firewall installed. The dialogue box requires the user to either permit or deny input. If the workstation is unattended the local attacker could select permit and enter information to the firewall program, without the legitimate user of the services knowledge.
Potentially this issue could allow unauthorized users to modify the Personal Tiny Firewal settings.
An issue has been reported in Tiny Personal Firewall which could allow a local attacker to permit users unauthorized access to Tiny Personal Firewall. Reportedly, this is possible even if the local system is locked.
Allegedly, a user scanning the network could initiate an alert dialogue in the foreground of a locked workstation with the firewall installed. The dialogue box requires the user to either permit or deny input. If the workstation is unattended the local attacker could select permit and enter information to the firewall program, without the legitimate user of the services knowledge.
Potentially this issue could allow unauthorized users to modify the Personal Tiny Firewal settings.
Exploit / POC
Tiny Personal Firewall Locked Terminal Bypass Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Tiny Personal Firewall Locked Terminal Bypass Vulnerability
Solution:
Maher Odeh <[email protected]> has reported that creating an appropriate rule and disabling the 'ask for action when rule is found' selection will address this issue.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Maher Odeh <[email protected]> has reported that creating an appropriate rule and disabling the 'ask for action when rule is found' selection will address this issue.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tiny Personal Firewall Locked Terminal Bypass Vulnerability
References:
References:
- Personal Firewall Homepage (Tiny Software)