UMN GopherD File Disclosure Vulnerability
BID:6776
Info
UMN GopherD File Disclosure Vulnerability
| Bugtraq ID: | 6776 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 1993 12:00AM |
| Updated: | Aug 09 1993 12:00AM |
| Credit: | The original discoverer of this vulnerability is unknown. |
| Vulnerable: |
University of Minnesota gopherd 2.0.3 University of Minnesota gopherd 2.0 + University of Minnesota gopherd 1.12 s University of Minnesota gopherd 1.12 |
| Not Vulnerable: |
University of Minnesota gopherd 2.0.4 University of Minnesota gopherd 1.12 S |
Discussion
UMN GopherD File Disclosure Vulnerability
UMN gopherd is prone to a remote file disclosure vulnerability. This may allow a remote attacker to retrieve sensitive local files from the host running the server. Vulnerable versions of gopherd do not drop privileges, so it is possible that arbitrary system files may be disclosed.
UMN gopherd is prone to a remote file disclosure vulnerability. This may allow a remote attacker to retrieve sensitive local files from the host running the server. Vulnerable versions of gopherd do not drop privileges, so it is possible that arbitrary system files may be disclosed.
Exploit / POC
UMN GopherD File Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
UMN GopherD File Disclosure Vulnerability
Solution:
This issue was addressed in versions released after August 6, 1993.
Solution:
This issue was addressed in versions released after August 6, 1993.
References
UMN GopherD File Disclosure Vulnerability
References:
References: