ID

VAR-200511-0475


CVE

CVE-2005-3468


TITLE

F-Secure Web Console Directory Traversal Vulnerability

Trust: 0.9

sources: BID: 15284 // CNNVD: CNNVD-200511-050

DESCRIPTION

Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files. The remote threat only arises if the application has been configured to accept connections from elsewhere. The default configuration only poses a local threat. This can be exploited to read arbitrary files on the server via directory traversal attacks. Successful exploitation requires that the attacker is able to connect to the Web Console via an allowed host. PROVIDED AND/OR DISCOVERED BY: The vendor credits Mikko Korppi. ORIGINAL ADVISORY: http://www.f-secure.com/security/fsc-2005-2.shtml ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse640-01_readme.txt ftp://ftp.f-secure.com/support/hotfix/fsig/fsigk642-01_readme.txt ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.35

sources: NVD: CVE-2005-3468 // BID: 15284 // VULHUB: VHN-14677 // PACKETSTORM: 41198

AFFECTED PRODUCTS

vendor:f securemodel:internet gatekeeperscope:eqversion:6.42

Trust: 1.9

vendor:f securemodel:internet gatekeeperscope:eqversion:6.41

Trust: 1.9

vendor:f securemodel:f-secure anti-virusscope:eqversion:6.40

Trust: 1.6

vendor:f securemodel:internet gatekeeperscope:eqversion:6.4

Trust: 1.6

vendor:f securemodel:internet gatekeeperscope:eqversion:6.400

Trust: 0.3

vendor:f securemodel:anti-virus for ms exchangescope:eqversion:6.40

Trust: 0.3

sources: BID: 15284 // CNNVD: CNNVD-200511-050 // NVD: CVE-2005-3468

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-3468
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200511-050
value: MEDIUM

Trust: 0.6

VULHUB: VHN-14677
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2005-3468
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-14677
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-14677 // CNNVD: CNNVD-200511-050 // NVD: CVE-2005-3468

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-3468

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200511-050

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200511-050

EXTERNAL IDS

db:BIDid:15284

Trust: 2.0

db:SECUNIAid:17361

Trust: 1.8

db:SECTRACKid:1015143

Trust: 1.7

db:SECTRACKid:1015142

Trust: 1.7

db:NVDid:CVE-2005-3468

Trust: 1.7

db:VUPENid:ADV-2005-2277

Trust: 1.7

db:CNNVDid:CNNVD-200511-050

Trust: 0.7

db:VULHUBid:VHN-14677

Trust: 0.1

db:PACKETSTORMid:41198

Trust: 0.1

sources: VULHUB: VHN-14677 // BID: 15284 // PACKETSTORM: 41198 // CNNVD: CNNVD-200511-050 // NVD: CVE-2005-3468

REFERENCES

url:http://www.f-secure.com/security/fsc-2005-2.shtml

Trust: 2.1

url:http://www.securityfocus.com/bid/15284

Trust: 1.7

url:http://securitytracker.com/id?1015142

Trust: 1.7

url:http://securitytracker.com/id?1015143

Trust: 1.7

url:http://secunia.com/advisories/17361

Trust: 1.7

url:http://www.vupen.com/english/advisories/2005/2277

Trust: 1.1

url:http://www.frsirt.com/english/advisories/2005/2277

Trust: 0.6

url:http://secunia.com/product/454/

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/17361/

Trust: 0.1

url:http://secunia.com/product/3339/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-14677 // BID: 15284 // PACKETSTORM: 41198 // CNNVD: CNNVD-200511-050 // NVD: CVE-2005-3468

CREDITS

Mikko Korppi

Trust: 0.6

sources: CNNVD: CNNVD-200511-050

SOURCES

db:VULHUBid:VHN-14677
db:BIDid:15284
db:PACKETSTORMid:41198
db:CNNVDid:CNNVD-200511-050
db:NVDid:CVE-2005-3468

LAST UPDATE DATE

2024-08-14T14:08:45.752000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-14677date:2011-03-08T00:00:00
db:BIDid:15284date:2005-11-02T00:00:00
db:CNNVDid:CNNVD-200511-050date:2005-11-03T00:00:00
db:NVDid:CVE-2005-3468date:2011-03-08T02:26:34.047

SOURCES RELEASE DATE

db:VULHUBid:VHN-14677date:2005-11-02T00:00:00
db:BIDid:15284date:2005-11-02T00:00:00
db:PACKETSTORMid:41198date:2005-11-03T01:02:14
db:CNNVDid:CNNVD-200511-050date:2005-11-02T00:00:00
db:NVDid:CVE-2005-3468date:2005-11-02T23:02:00