Red Hat Interchange Arbitrary File Read Vulnerability
BID:5453
Info
Red Hat Interchange Arbitrary File Read Vulnerability
| Bugtraq ID: | 5453 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2002 12:00AM |
| Updated: | Aug 13 2002 12:00AM |
| Credit: | Vulnerability first detailed in the product changelog. |
| Vulnerable: |
Redhat Interchange 4.8.5 Redhat Interchange 4.8.4 Redhat Interchange 4.8.3 Redhat Interchange 4.8.2 Redhat Interchange 4.8.1 |
| Not Vulnerable: |
Redhat Interchange 4.8.6 |
Discussion
Red Hat Interchange Arbitrary File Read Vulnerability
A vulnerability has been reported for Interchange 4.8.5 and earlier. Reportedly, Interchange may disclose contents of files to attackers.
The vulnerability occurs due to the placement of the 'doc' folder. Reportedly, the folder will be installed as follows: <INTERCHANGE_ROOT>/doc. This folder, by default, contains Interchange man pages. This vulnerability is only exploitable when the Interchange service runs in INET (Internet service) mode.
An attacker may exploit this vulnerability to the contents of restricted files accessible to the Interchange process.
It has been reported that this issue may be exploited through a '../' directory traversal sequence in a HTTP request to the vulnerable server.
A vulnerability has been reported for Interchange 4.8.5 and earlier. Reportedly, Interchange may disclose contents of files to attackers.
The vulnerability occurs due to the placement of the 'doc' folder. Reportedly, the folder will be installed as follows: <INTERCHANGE_ROOT>/doc. This folder, by default, contains Interchange man pages. This vulnerability is only exploitable when the Interchange service runs in INET (Internet service) mode.
An attacker may exploit this vulnerability to the contents of restricted files accessible to the Interchange process.
It has been reported that this issue may be exploited through a '../' directory traversal sequence in a HTTP request to the vulnerable server.
Exploit / POC
Red Hat Interchange Arbitrary File Read Vulnerability
This vulnerability may be exploited with a web browser. The following example has been submitted:
http://www.domain.com:7786/../../../../../../../../../etc/passwd
This vulnerability may be exploited with a web browser. The following example has been submitted:
http://www.domain.com:7786/../../../../../../../../../etc/passwd
Solution / Fix
Red Hat Interchange Arbitrary File Read Vulnerability
Solution:
The following upgrades are available:
Redhat Interchange 4.8.1
Redhat Interchange 4.8.2
Redhat Interchange 4.8.3
Redhat Interchange 4.8.4
Redhat Interchange 4.8.5
Solution:
The following upgrades are available:
Redhat Interchange 4.8.1
-
RedHat interchange-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-4.8. 6-1.i386.rpm -
RedHat interchange-foundation-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-4.8.6-1.i386.rpm -
RedHat interchange-foundation-demo-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-demo-4.8.6-1.i386.rpm
Redhat Interchange 4.8.2
-
RedHat interchange-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-4.8. 6-1.i386.rpm -
RedHat interchange-foundation-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-4.8.6-1.i386.rpm -
RedHat interchange-foundation-demo-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-demo-4.8.6-1.i386.rpm
Redhat Interchange 4.8.3
-
Debian interchange-cat-foundation_4.8.3.20020306-1.woody.1_all.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange -cat-foundation_4.8.3.20020306-1.woody.1_all.deb -
Debian interchange-ui_4.8.3.20020306-1.woody.1_all.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange -ui_4.8.3.20020306-1.woody.1_all.deb -
Debian interchange_4.8.3.20020306-1.woody.1_alpha.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_alpha.deb -
Debian interchange_4.8.3.20020306-1.woody.1_arm.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_arm.deb -
Debian interchange_4.8.3.20020306-1.woody.1_hppa.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_hppa.deb -
Debian interchange_4.8.3.20020306-1.woody.1_i386.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_i386.deb -
Debian interchange_4.8.3.20020306-1.woody.1_ia64.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_ia64.deb -
Debian interchange_4.8.3.20020306-1.woody.1_m68k.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_m68k.deb -
Debian interchange_4.8.3.20020306-1.woody.1_mips.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_mips.deb -
Debian interchange_4.8.3.20020306-1.woody.1_mipsel.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_mipsel.deb -
Debian interchange_4.8.3.20020306-1.woody.1_powerpc.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_powerpc.deb -
Debian interchange_4.8.3.20020306-1.woody.1_s390.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_s390.deb -
Debian interchange_4.8.3.20020306-1.woody.1_sparc.deb
http://security.debian.org/pool/updates/main/i/interchange/interchange _4.8.3.20020306-1.woody.1_sparc.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_alpha.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_alpha.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_arm.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_arm.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_hppa.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_hppa.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_i386.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_i386.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_ia64.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_ia64.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_m68k.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_m68k.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_mips.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_mips.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_mipsel.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_mipsel.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_powerpc.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_powerpc.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_s390.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_s390.deb -
Debian libapache-mod-interchange_4.8.3.20020306-1.woody.1_sparc.deb
http://security.debian.org/pool/updates/main/i/interchange/libapache-m od-interchange_4.8.3.20020306-1.woody.1_sparc.deb -
RedHat interchange-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-4.8. 6-1.i386.rpm -
RedHat interchange-foundation-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-4.8.6-1.i386.rpm -
RedHat interchange-foundation-demo-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-demo-4.8.6-1.i386.rpm
Redhat Interchange 4.8.4
-
RedHat interchange-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-4.8. 6-1.i386.rpm -
RedHat interchange-foundation-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-4.8.6-1.i386.rpm -
RedHat interchange-foundation-demo-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-demo-4.8.6-1.i386.rpm
Redhat Interchange 4.8.5
-
RedHat interchange-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-4.8. 6-1.i386.rpm -
RedHat interchange-foundation-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-4.8.6-1.i386.rpm -
RedHat interchange-foundation-demo-4.8.6-1.i386.rpm
http://ftp.interchange.redhat.com/interchange/4.8/rpm/interchange-foun dation-demo-4.8.6-1.i386.rpm
References
Red Hat Interchange Arbitrary File Read Vulnerability
References:
References:
- [ic] IMPORTANT: Workaround for IC problem (Mike Heins)
- Interchange Product Page (RedHat)