Date: 11 January 2007
References: ESB-2007.0016
Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
AusCERT Update AU-2007.0002 - [Win]
ColdFusion vulnerability allows reading of file contents
11 January 2007
AusCERT Update Summary
----------------------
Product: ColdFusion MX 7.0.2 and prior
Publisher: iDefense
Operating System: Windows
Impact: Read-only Data Access
Access: Remote/Unauthenticated
CVE Names: CVE-2006-5858
Ref: ESB-2007.0016
Original Bulletin:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=466
Comment: iDefense provides some further information about the disclosure
vulnerability announced by Adobe yesterday, stating that it
actually allows reading the contents of arbitrary files, not just
reading directory listings as stated in the Adobe advisory.
In particular, if passwords are either hard-coded or stored in
web application scripts or data files then this vulnerability
may increase the risk of further compromise.
- --------------------------BEGIN INCLUDED TEXT--------------------
Adobe Macromedia ColdFusion Source Code Disclosure Vulnerability
iDefense Security Advisory 01.09.07
http://labs.idefense.com/intelligence/vulnerabilities/
Jan 09, 2007
I. BACKGROUND
Adobe Macromedia ColdFusion is an application server and development
framework for websites. More information is available at the following
URL.
http://www.adobe.com/products/coldfusion/
II. DESCRIPTION
Remote exploitation of an input validation vulnerability in Adobe Systems
Inc.'s Macromedia ColdFusion MX 7 may allow an attacker to view file
contents on the server.
The vulnerability specifically exists in that URL encoded filenames will
be decoded by the IIS process and then again by the ColdFusion process. By
supplying a URL containing a double encoded null byte and an extension
handled by ColdFusion, such as '.cfm', it is possible to view the contents
of any file which is not interpreted by ColdFusion.
III. ANALYSIS
Successful exploitation would allow a remote attacker to view the contents
of a file on the affected server. Depending on the layout of the files on
the server, this could include configuration files, source code written in
another scripting language, log files or other data files. Although this
vulnerability does not in itself allow execution of code on the server, it
may allow an attacker to discover sensitive information such as passwords
or to discover vulnerabilities in other scripts on the system or
potentially bypass some security restrictions.
IV. DETECTION
iDefense has confirmed this vulnerability exists in Adobe Macromedia
ColdFusion MX 7.0.2, with all available fixes, running on Microsoft IIS
vulnerable.
V. WORKAROUND
iDefense is unaware of any effective workarounds for this vulnerability.
VI. VENDOR RESPONSE
Adobe has released a patch for this issue. For more information consult
their advisory at the link below.
http://www.adobe.com/support/security/bulletins/apsb07-02.html
VII. CVE INFORMATION
The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2006-5858 to this issue. This is a candidate for inclusion in
the CVE list (http://cve.mitre.org/), which standardizes names for
security problems.
VIII. DISCLOSURE TIMELINE
11/08/2006 Initial vendor notification
11/09/2006 Initial vendor response
01/09/2007 Coordinated public disclosure
IX. CREDIT
This vulnerability was reported to iDefense by Inge Henriksen.
Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php
Free tools, research and upcoming events
http://labs.idefense.com/
X. LEGAL NOTICES
Copyright © 2006 iDefense, Inc.
Permission is granted for the redistribution of this alert electronically.
It may not be edited in any way without the express written consent of
iDefense. If you wish to reprint the whole or any part of this alert in
any other medium other than electronically, please e-mail
customerservice@idefense.com for permission.
Disclaimer: The information in the advisory is believed to be accurate at
the time of publishing based on currently available information. Use of
the information constitutes acceptance for use in an AS IS condition.
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct, indirect,
or consequential loss or damage arising from use of, or reliance on, this
information.
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
http://www.auscert.org.au/render.html?cid=1980
If you believe that your computer system has been compromised or attacked in
any way, we encourage you to let us know by completing the secure National IT
Incident Reporting Form at:
http://www.auscert.org.au/render.html?it=3192
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967
iQCVAwUBRaWZYSh9+71yA2DNAQLqnwP+IgwORT/QCoxXE+Lm7gBLxmbBiw7MjrtN
R50tdx0QmGKUDblGJrUJbs9GU+jEeE/Omd6mw8DF1ag4AvoK9zCuiQikmutjW/Qp
CJon70DyWqwLEJWZ7UWIT3ndnHAkZjpp3U16BUlz3N9QDe2q07qCx1ZCbsxMnY1v
BCBo7A1sOzg=
=UMLb
-----END PGP SIGNATURE-----
|