Kiwi CatTools contains a flaw that allows a remote attacker to grab and put files outside of the tftp root path. The issue is due to the KiwiTFTP.dll server component does not properly sanitizing user input, specifically directory traversal style attacks ([character]//..//) supplied via the get and put commands resulting in a loss of confidentiality. This flaw could possible lead to further attacks on the system by uploading arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to Kiwi CatTools version 3.2.9 or higher, as it has been reported to fix this vulnerability. In addition, Kiwi Enterprises has released a patch to upgrade the "KiwiTFTP.dll" file to version 1.0.0.8.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.