GNUMP3d: Directory traversal and XSS vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200511-05 / gnump3d |
| Release Date |
November 06, 2005 |
| Latest Revision |
August 21, 2007: 02 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| media-sound/gnump3d |
<
2.9_pre7 |
>=
2.9_pre7 |
All supported architectures
|
Related bugreports:
#109667
Synopsis
GNUMP3d is vulnerable to directory traversal and cross-site scripting
attacks that may result in information disclosure or the compromise of a
browser.
2.
Impact Information
Background
GNUMP3d is a streaming server for MP3s, OGG vorbis files, movies and
other media formats.
Description
Steve Kemp reported about two cross-site scripting attacks that are
related to the handling of files (CVE-2005-3424, CVE-2005-3425). Also
reported is a directory traversal vulnerability which comes from the
attempt to sanitize input paths (CVE-2005-3123).
Impact
A remote attacker could exploit this to disclose sensitive information
or inject and execute malicious script code, potentially compromising
the victim's browser.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All GNUMP3d users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9_pre7"
|
4.
References
|