The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


DDIVRT-2008-10 PacketTrap TFTP Directory Traversal Vulnerability


<< Previous INDEX Search src / Print Next >>
Date: 3 Mar 2008 14:18:45 -0000
From: [email protected]
To: [email protected]
Subject: DDIVRT-2008-10 PacketTrap TFTP Directory Traversal Vulnerability
X-Virus-Scanned: antivirus-gw at tyumen.ru

Title
DDIVRT-2008-10 PacketTrap PT360 Tool Suite TFTP Arbitrary File Access

Severity
High

Discovered By
Digital Defense, Inc. Vulnerability Research Team
Credit: princeofnigeria and r@b13$

Date Discovered
1/29/2008

Vulnerability Description
DDI VRT staff notified PacketTrap Networks, Inc. on February 7, 2008 of a flaw within the PacketTrap PT360 suite.  Specifically, the default installation of the PacketTrap PT360 Tool Suite Version 1.1.33.1.0 TFTP server component is susceptible to directory traversal attack. A remote or local attacker can exploit this flaw to retrieve arbitrary files outside of the TFTP server root directory.  This vulnerability also allows a remote attacker to overwrite and modify system files which could facilitate a full system compromise.

Solution Description
PacketTrap Networks, Inc. released a patch (#3302) for this flaw on February 29, 2008.  

Tested Systems / Software (with versions)
------------------------------------------
Windows XP Professional Service Pack 2, PacketTrap PT360 Tool Suite Version 1.1.33.1.0.  Other versions may be vulnerable.

Vendor Contact
Name: PacketTrap Networks, Inc.
Website: http://www.packettrap.com/


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру