Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
BID:57163
Info
Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
| Bugtraq ID: | 57163 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4696 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2013 12:00AM |
| Updated: | Jan 04 2013 12:00AM |
| Credit: | Paul Johnston |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
Eye-Fi Helper is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may exploit this vulnerability to overwrite arbitrary files from the vulnerable computer in the context of the affected application. This may result in denial-of-service conditions; other attacks may also be possible.
Eye-Fi Helper versions prior to 3.4.23 are vulnerable.
Eye-Fi Helper is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may exploit this vulnerability to overwrite arbitrary files from the vulnerable computer in the context of the affected application. This may result in denial-of-service conditions; other attacks may also be possible.
Eye-Fi Helper versions prior to 3.4.23 are vulnerable.
Exploit / POC
Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
An exploit is available; please see the references for more information.
An exploit is available; please see the references for more information.
Solution / Fix
Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Eye-Fi Helper CVE-2011-4696 Directory Traversal Vulnerability
References:
References:
- Directory traversal in Eye-Fi Helper < 3.4.23 (Pentest Limited)
- Eye-Fi HomePage (Eye-Fi)