lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060317020520.9569F1EEF@lists.grok.org.uk> Date: Fri Mar 17 02:36:36 2006 From: krahmer at suse.de (Sebastian Krahmer) Subject: Advisory * +Thu Mar 16 21:05:17 EST 2006+ * Directory Transversal in ISC INN Advisory * +Thu Mar 16 21:05:17 EST 2006+ * Directory Transversal in ISC INN +++++++++++++++++++++++++++++++++++++++++++ I. Description Remote exploitation of a directory traversal vulnerability in ISC INN could allow attackers to overwrite or view arbitrary files with user-supplied contents. +++++++++++++++++++++++++++++++++++++++++++ II. History 18-2-2006 - Vendor Reply. 16-3-2006 - Public Disclosure. +++++++++++++++++++++++++++++++++++++++++++ III. Workaround This vulnerability had no workarounds on the vulnerability at hand. +++++++++++++++++++++++++++++++++++++++++++ IV. Vendor Response ISC INN is extended no identified explanation about this vulnerability indentified. +++++++++++++++++++++++++++++++++++++++++++ Appendix A Vendor Information http://www.isc.org/index.pl?/sw/inn/ +++++++++++++++++++++++++++++++++++++++++++ Appendix B References RFC 6489