OSVDB ID: 14365

Title: xli Compressed Image Filename Shell Metacharacter Arbitrary Command Execution

Info

Disclosure

Mar 02, 2005

Discovery

Jan 01, 2001

Dates

Exploit

Jan 01, 2001

Solution

Unknown

Description

xli contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to the handling of compressed images. With a specially crafted filename containing shell meta characters, a remote attacker could execute arbitrary commands resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.17.0-r1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

GraemeĀ Gill

xli

1.16

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/14365