DCGUI Remote Directory Parsing File Download Vulnerability
BID:6760
Info
DCGUI Remote Directory Parsing File Download Vulnerability
| Bugtraq ID: | 6760 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2003 12:00AM |
| Updated: | Jan 22 2003 12:00AM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
qt-dcgui qt-dcgui 0.2.1 qt-dcgui qt-dcgui 0.2 dcgui dcgui 0.2.1 dcgui dcgui 0.2 |
| Not Vulnerable: |
qt-dcgui qt-dcgui 0.2.4 qt-dcgui qt-dcgui 0.2.2 dcgui dcgui 0.2.4 dcgui dcgui 0.2.3 dcgui dcgui 0.2.2 |
Discussion
DCGUI Remote Directory Parsing File Download Vulnerability
A vulnerability has been discovered in versions of dcgui prior to 0.2.2. A flaw exists in the directory parsing which could allow an attacker to obtain files outside of the hosts sharelist. This problem also affects the qt-dcgui program, which is likely a derivative of the same source code base.
The precise technical details regarding this issue are not yet known. Although unconfirmed it is likely that this vulnerability can be exploited due to a directory traversal bug.
A vulnerability has been discovered in versions of dcgui prior to 0.2.2. A flaw exists in the directory parsing which could allow an attacker to obtain files outside of the hosts sharelist. This problem also affects the qt-dcgui program, which is likely a derivative of the same source code base.
The precise technical details regarding this issue are not yet known. Although unconfirmed it is likely that this vulnerability can be exploited due to a directory traversal bug.