BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
BID:56488
Info
BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
| Bugtraq ID: | 56488 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5171 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2012 12:00AM |
| Updated: | Nov 12 2012 12:00AM |
| Credit: | Ryohei Koike from Sakura Information Systems |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
BeZIP is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to create or overwrite arbitrary files on the computer running the affected application. This may aid in further attacks.
BeZIP prior to 3.10 are vulnerable; other versions may also be affected.
BeZIP is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to create or overwrite arbitrary files on the computer running the affected application. This may aid in further attacks.
BeZIP prior to 3.10 are vulnerable; other versions may also be affected.
Exploit / POC
BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
Attackers may exploit this issue by creating malicious archive files that include files with directory-traversal strings ('../').
Attackers may exploit this issue by creating malicious archive files that include files with directory-traversal strings ('../').
Solution / Fix
BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
BE-GRAPH BeZIP CVE-2012-5171 Directory Traversal Vulnerability
References:
References: