Vissza a www.andrews.hu-ra

    [guru] [remove-vuln@secunia.com: Secunia Research: Trend Micro OfficeScan Directory Traversal Vulnerability]


    DATE: Mon, 13 Oct 2008 21:04:24 +0200
    Directory traversal hib�tal�ak a Trend Micro OfficeScan term�nek
    TmListen.exe programj�n.
    
    
    --- Begin Message ---
    ====================================================================== 
    
                         Secunia Research 02/10/2008
    
        - Trend Micro OfficeScan Directory Traversal Vulnerability -
    
    ====================================================================== 
    Table of Contents
    
    Affected Software....................................................1
    Severity.............................................................2
    Vendor's Description of Software.....................................3
    Description of Vulnerability.........................................4
    Solution.............................................................5
    Time Table...........................................................6
    Credits..............................................................7
    References...........................................................8
    About Secunia........................................................9
    Verification........................................................10
    
    ====================================================================== 
    1) Affected Software 
    
    * Trend Micro OfficeScan 7.3 patch 4 build 1367
    
    NOTE: Other versions may also be affected.
    
    ====================================================================== 
    2) Severity 
    
    Rating: Less critical
    Impact: Information disclosure
    Where:  Local network
    
    ====================================================================== 
    3) Vendor's Description of Software 
    
    "Protect your desktops, laptops, and file servers with OfficeScan?,
    comprehensive security against today?s complex, blended threats and
    Web-based attacks."
    
    Product Link:
    http://us.trendmicro.com/us/products/enterprise/officescan-client-server-edition/
    
    ====================================================================== 
    4) Description of Vulnerability
    
    Secunia Research has discovered a vulnerability in Trend Micro 
    OfficeScan, which can be exploited by malicious people to gain 
    knowledge of sensitive information.
    
    The vulnerability is caused by an input validation error in 
    TmListen.exe when a client is configured to be an update agent. This
    can be exploited to retrieve arbitrary files from the system via 
    directory traversal attacks.
    
    ====================================================================== 
    5) Solution 
    
    Apply patches available from the vendor.
    
    
    ====================================================================== 
    6) Time Table 
    
    15/09/2008 - Vendor notified.
    15/09/2008 - Vendor response.
    02/10/2008 - Public disclosure.
    
    ====================================================================== 
    7) Credits 
    
    Discovered by Dyon Balding, Secunia Research.
    
    ====================================================================== 
    8) References
    
    The Common Vulnerabilities and Exposures (CVE) project has assigned 
    CVE-2008-2439 for the vulnerability.
    
    ====================================================================== 
    9) About Secunia
    
    Secunia offers vulnerability management solutions to corporate
    customers with verified and reliable vulnerability intelligence
    relevant to their specific system configuration:
    
    http://secunia.com/advisories/business_solutions/
    
    Secunia also provides a publicly accessible and comprehensive advisory
    database as a service to the security community and private 
    individuals, who are interested in or concerned about IT-security.
    
    http://secunia.com/advisories/
    
    Secunia believes that it is important to support the community and to
    do active vulnerability research in order to aid improving the 
    security and reliability of software in general:
    
    http://secunia.com/secunia_research/
    
    Secunia regularly hires new skilled team members. Check the URL below
    to see currently vacant positions:
    
    http://secunia.com/corporate/jobs/
    
    Secunia offers a FREE mailing list called Secunia Security Advisories:
    
    http://secunia.com/advisories/mailing_lists/
    
    ====================================================================== 
    10) Verification 
    
    Please verify this advisory by visiting the Secunia website:
    http://secunia.com/secunia_research/2008-39/
    
    Complete list of vulnerability reports published by Secunia Research:
    http://secunia.com/secunia_research/
    
    ======================================================================
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra