SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Caucho Resin Windows Directory Traversal Vulnerability


Arrow  SecurityAlert : 904
Arrow  CVE : CVE-2006-1953
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : advisory rapid7 com
Arrow  Published : 18.05.2006

Arrow  Affected Software : Caucho Resin v3.0.18 for Windows
Caucho Resin v3.0.17 for Windows



Arrow  Advisory Content :  

_______________________________________________________________________
Rapid7 Security Advisory
Visit http://www.rapid7.com/ to download NeXpose,
SC Magazine Winner of Best Vulnerability Management product.
_______________________________________________________________________

Rapid7 Advisory R7-0024
Caucho Resin Windows Directory Traversal Vulnerability

Published: May 16, 2006
Revision: 1.0
http://www.rapid7.com/advisories/R7-0024.html

CVE: CVE-2006-1953

1. Affected system(s):

KNOWN VULNERABLE:
o Caucho Resin v3.0.18 for Windows
o Caucho Resin v3.0.17 for Windows

NOT VULNERABLE:
o Caucho Resin v3.0.19
o Caucho Resin v3.0.16 and earlier

2. Summary

The Caucho Resin web application server for Windows contains a
directory traversal vulnerability that allows remote
unauthenticated users to download any file from the system. It is
possible to download files from any drive on the system.

Rapid7 have updated NeXpose to check for this vulnerability. Licensed
customers will receive the new vulnerability checks automatically.
Visit http://www.rapid7.com to register for a free demo of NeXpose.

3. Vendor status and information

Caucho Technology, Inc.
http://www.caucho.com/

Caucho was notified of this vulnerability on April 20th, 2006.
They fixed this vulnerability in the latest unofficial snapshot
of Resin 3.0.19, available from Caucho's website.

4. Solution

Upgrade to the latest snapshot version of Resin, version 3.0.19.

5. Detailed analysis

Caucho Resin is a servlet and JSP server. Resin ships with its own
standalone web server which runs by default on port 8080. Any remote
user can request URLs of the form:

http://victim:8080/C:%5C/

to access the root of the C: drive (and any files below it). Any
drive letter can be specified. Only Resin on Windows is vulnerable.

This vulnerability appears to have been introduced in Resin
version 3.0.17, although this has not been confirmed by the vendor.

6. Contact Information

Rapid7 Security Advisories
Email: advisory (at) rapid7 (dot) com [email concealed]
Web: http://www.rapid7.com/
Phone: +1 (617) 603-0700

7. Disclaimer and Copyright

Rapid7, LLC is not responsible for the misuse of the information
provided in our security advisories. These advisories are a service
to the professional security community. There are NO WARRANTIES
with regard to this information. Any application or distribution of
this information constitutes acceptance AS IS, at the user's own
risk. This information is subject to change without notice.

This advisory Copyright (C) 2006 Rapid7, LLC. Permission is
hereby granted to redistribute this advisory, providing that no
changes are made and that the copyright notices and disclaimers
remain intact.





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.