net6 Session Hijacking and Information Disclosure Vulnerabilities
BID:50442
Info
net6 Session Hijacking and Information Disclosure Vulnerabilities
| Bugtraq ID: | 50442 |
| Class: | Design Error |
| CVE: |
CVE-2011-4091 CVE-2011-4093 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2011 12:00AM |
| Updated: | Apr 13 2015 09:17PM |
| Credit: | Vasiliy Kulikov |
| Vulnerable: |
0x539 dev group net6 1.3.13 |
| Not Vulnerable: | |
Discussion
net6 Session Hijacking and Information Disclosure Vulnerabilities
net6 is prone to a session-hijacking vulnerability and an information-disclosure vulnerability.
An attacker can exploit these vulnerabilities to obtain sensitive information, or possibly perform actions with elevated privileges.
net6 1.3.13 is vulnerable; other versions may also be affected.
net6 is prone to a session-hijacking vulnerability and an information-disclosure vulnerability.
An attacker can exploit these vulnerabilities to obtain sensitive information, or possibly perform actions with elevated privileges.
net6 1.3.13 is vulnerable; other versions may also be affected.
Exploit / POC
net6 Session Hijacking and Information Disclosure Vulnerabilities
An attacker can use readily available network utilities to exploit these issues.
An attacker can use readily available network utilities to exploit these issues.
Solution / Fix
net6 Session Hijacking and Information Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
net6 Session Hijacking and Information Disclosure Vulnerabilities
References:
References:
- 3 flaws in libobby and libnet6 (Vasiliy Kulikov)
- GIT Commit: Avoid duplicate IDs on unsigned integer overflow (Armin Burgmeier)
- GIT Commit: Run custom authentication before checking for the user name (Armin Burgmeier)
- net6 Project Page (0x539 dev group)