Secunia Advisory SA23880GeoIP C API "GeoIP_update_database_general()" Directory Traversal
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Dean Gaudet has reported a vulnerability in GeoIP, which can be exploited by malicious people to overwrite arbitary files on a user's system. The "GeoIP_update_database_general()" function does not correctly sanitise the filename returned from the update server. This can be exploited by e.g. a malicious update server via directory traversal attacks to overwrite arbitrary files with the privileges of the user running the update. The vulnerability is reported in versions prior to 1.4.1. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||
74 views | ![]() |
Debian update for linux-2.6![]() | |
63 views | ![]() |
Debian update for moin![]() | |
122 views | ![]() |
| Ubuntu update for MoinMoin | |