OSVDB ID: 6608

Title: Tripwire Email Report Format String Arbitrary Code Execution

Info

Disclosure

Jun 02, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Tripwire contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when creating a file with a specially crafted filename which may be included in the email report and passed to the fprintf() function. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Paul Herman has released a patch to address this vulnerability.

Products

Tripwire, Inc.

Tripwire (Commercial)

2.4
3.x
4.0.0
4.0.1

Tripwire (Open Source)

2.3.1

References

Credit

  • Paul Herman - phermanfrenchfries.net -


Direct URL: http://osvdb.org/6608