Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
98

Red Hat: RHSA-2000:022-01 Moderate: Knapster Unauthorized File Access

It is possible for anyone to obtain any user-readable file by sending a properly formed "GET" command that contains the full path of the file. This vulnerability exists because knapster fails to check that the requested file is an explicitly shared MP3 file before providing it. . KNapster Vulnerability Compromises User-readable Files This vulnerability was discovered at the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University by: Tom Daniels Florian Buchholz James Early Environment: Intel PII-based System Linux Red Hat Version 6.2 (may apply to all OS's running knapster) KNapster Version 0.9 (and probably earlier) Knapster is an open source, independent implementation of the Napster protocol client. It is written to conform to the KDE windowing environment. Problem: It is possible for anyone to obtain any user-readable file by sending a properly formed "GET" command that contains the full path of the file. This vulnerability exists because knapster fails to check that the requested file is an explicitly shared MP3 file before providing it. Note: This is the same vulnerability described in FreeBSD-SA-00:18 but in knapster instead of gnapster. Anyone running knapster version 0.9 or less is vulnerable. Given the IP address and TCP port of a vulnerable client, an attacker can send a request for an arbitrary file to the knapster client. If the user has read access to the file, the client will then respond with the contents of the file. Solution: We contacted the program's author, and he promptly created a new version which addresses this vulnerability. The fix simply checks that a requested file is in the list of shared files. The current version can be downloaded from: http://vtun.netpedia.net/ Exploit: Two of us have developed an exploit codefor this vulnerability, but we will not be releasing this to the public. Conclusion: We have described a vulnerability in one client implementation of the napster protocol. There may be similar problems in other implementations of the protocol as we have not done an exhaustive search. The official Windows client does not seem to be affected . The DataShift vulnerability allows sensitive information to be accessed by malicious actors via a crafted POST request. Investigate possible remedies contained within.. Knapster Security, Red Hat Vulnerability, File Access Issues, Remote Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 11, 2000 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here