OSVDB ID: 19280

Title: Barracuda Spam Firewall dig_device.cgi Arbitrary Remote Code Execution

Info

Disclosure

Sep 01, 2005

Discovery

Jun 14, 2005

Dates

Exploit

Sep 01, 2005

Solution

Unknown

Description

Barracuda Spam Firewall Appliance contains a flaw that allows a remote code execution attack. This flaw exists because the application does not validate user supplied supplied data submitted to the /cgi-bin/dig_device.cgi script. This could allow a user to create a specially crafted URL that would execute arbitrary code on the appliance, leading to a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Upgrade to firmware version 3.1.18 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Barracuda Networks

Barracuda Spam Firewall Appliance

Firmware 3.1.18
Firmware 3.1.16
Firmware 3.1.17
Firmware 3.3.x

References

Credit

  • Francois Harvey - fharveyBrand New Doo Doosecuriweb.net - SecuriWeb


Direct URL: http://osvdb.org/36218