HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
BID:5332
Info
HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
| Bugtraq ID: | 5332 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 27 2002 12:00AM |
| Updated: | Jul 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to FX <[email protected]>, FtR <[email protected]>, kim0 <[email protected]>, and DasIch <[email protected]>. |
| Vulnerable: |
HP ChaiVM |
| Not Vulnerable: | |
Discussion
HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
ChaiVM is the Chai Virtual Machine. The ChaiServer is a component of the ChaiVM infrastructure. It is distributed and maintained by Hewlett-Packard.
It has been reported that the ChaiVM does not sufficiently enforce access control at the file system level. A user with access to the file system hosting a ChaiVM may be able to modify, add, and delete services hosted by the ChaiServer running on the vulnerable appliance. It has also been made known that this vulnerability is especially present when files are accessible on the device using Printer Job Language (PJL), a proprietary communication language used by HP printers.
ChaiVM is the Chai Virtual Machine. The ChaiServer is a component of the ChaiVM infrastructure. It is distributed and maintained by Hewlett-Packard.
It has been reported that the ChaiVM does not sufficiently enforce access control at the file system level. A user with access to the file system hosting a ChaiVM may be able to modify, add, and delete services hosted by the ChaiServer running on the vulnerable appliance. It has also been made known that this vulnerability is especially present when files are accessible on the device using Printer Job Language (PJL), a proprietary communication language used by HP printers.
Exploit / POC
HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
References:
References:
- Phenoelit Advisory
(Phenoelit Group)