Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
BID:4353
Info
Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
| Bugtraq ID: | 4353 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0489 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Linux Directory Penguin nslookup 1.0 |
| Not Vulnerable: | |
Discussion
Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
Penguin nslookup.pl is a freely available, open source script for tracing network hops from a web server. It is distributed by Linux Directory.
The Penguin nslookup script does not adequately filter special characters. This makes it possible for a remote user to access specific files on the local system. The attacker may read files that are accessible by the web server. Additionally, the attacker may be able to execute arbitrary commands with the permissions of the web server by encapsulating commands in special characters.
Penguin nslookup.pl is a freely available, open source script for tracing network hops from a web server. It is distributed by Linux Directory.
The Penguin nslookup script does not adequately filter special characters. This makes it possible for a remote user to access specific files on the local system. The attacker may read files that are accessible by the web server. Additionally, the attacker may be able to execute arbitrary commands with the permissions of the web server by encapsulating commands in special characters.
Exploit / POC
Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
References:
References:
- Penguin Traceroute Homepage (Linux Directory)