BigIP Config UI Vulnerabilities
BID:778
Info
BigIP Config UI Vulnerabilities
| Bugtraq ID: | 778 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 08 1999 12:00AM |
| Updated: | Nov 08 1999 12:00AM |
| Credit: | This was posted to BugTraq by Guy Cohen <[email protected]> on Nov 8, 1999. |
| Vulnerable: |
F5 BIG-IP 2.0 |
| Not Vulnerable: |
F5 BIG-IP 2.1 |
Discussion
BigIP Config UI Vulnerabilities
BigIP is a load balancing system from F5 software. It has a web-based configuration system, which is vulnerable to several standard CGI attacks. According to Guy Cohen <[email protected]>, it is possible to view arbitrary files on the BSDI system which it is installed on. To add to this, the configuration program is installed setuid root. This is considered a local vulnerability since htaccess authentication is required to get to the configuration area. No more information on this vulnerability is available.
BigIP is a load balancing system from F5 software. It has a web-based configuration system, which is vulnerable to several standard CGI attacks. According to Guy Cohen <[email protected]>, it is possible to view arbitrary files on the BSDI system which it is installed on. To add to this, the configuration program is installed setuid root. This is considered a local vulnerability since htaccess authentication is required to get to the configuration area. No more information on this vulnerability is available.
Exploit / POC
BigIP Config UI Vulnerabilities
See discussion.
See discussion.
Solution / Fix
BigIP Config UI Vulnerabilities
Solution:
F5 Software has acknowledged the problem (as of Nov 8, 1999).
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
F5 Software has acknowledged the problem (as of Nov 8, 1999).
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].