ht://dig Remote Command Execution Vulnerability
BID:867
Info
ht://dig Remote Command Execution Vulnerability
| Bugtraq ID: | 867 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 1999 12:00AM |
| Updated: | Dec 09 1999 12:00AM |
| Credit: | First exposed in a Debian GNU/Linux security advisory published on Dec 9, 1999. |
| Vulnerable: |
Debian Linux 2.1 |
| Not Vulnerable: | |
Discussion
ht://dig Remote Command Execution Vulnerability
ht://dig is a program which is shipped with Debian GNU/Linux 2.1 that is used for indexing and searching files on webservers. When it attempts to handle non-HTML files, it calls an external program with the document as a parameter - without checking for shell escapes. If files can be created with filenames containing shell escapes, it may be possible to execute aribtrary shell commands on the target webserver due to this problem, leading to a remote compromise.
ht://dig is a program which is shipped with Debian GNU/Linux 2.1 that is used for indexing and searching files on webservers. When it attempts to handle non-HTML files, it calls an external program with the document as a parameter - without checking for shell escapes. If files can be created with filenames containing shell escapes, it may be possible to execute aribtrary shell commands on the target webserver due to this problem, leading to a remote compromise.