From f7ae660ebe22724b64f9d0543c42973a5ec4aff2 Mon Sep 17 00:00:00 2001 From: nectar Date: Thu, 12 Aug 2004 18:56:10 +0000 Subject: Under certain configurations of POPfile may allow an attacker to retrieve files from the victim's machine. Reported by: Daniel Grund --- security/vuxml/vuln.xml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) (limited to 'security/vuxml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index bc897837bb53..3e92cad95cbb 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,31 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + popfile file disclosure + + + popfile + 0.21.1_2 + + + + +

John Graham-Cumming reports that certain configurations of + POPFile may allow the retrieval of any files with the + extensions .gif, .png, .ico, .css, as well as some files with + the extension .html.

+ +
+ + http://sourceforge.net/mailarchive/forum.php?thread_id=5248725&forum_id=12356 + + + 2004-08-02 + 2004-08-12 + +
+ Multiple Potential Buffer Overruns in Samba -- cgit