OSVDB ID: 6107

Title: Multiple Browser Telnet URI Handler File Manipulation

Info

Disclosure

May 12, 2004

Discovery

Unknown

Dates

Exploit

May 12, 2004

Solution

Unknown

Description

Several browsers contain a flaw that may allow a remote attacker arbitrary file manipulation. The issue is triggered when a specially crafted telnet URI is parsed by the browser resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Apple Computer, Inc.

Safari

1.2

KDE Project

Konqueror

3.2.1

MacWarriors

TrailBlazer

0.52

Microsoft Corporation

Internet Explorer for Mac OS X

5.2.3

Internet Explorer for Windows

6 SP1

Mozilla Organization

Firefox for Linux

0.8

Firefox for Mac OS X

0.8

Firefox for Windows

0.8

Opera Software

Opera

7.23

The Omni Group

OmniWeb

4.5

iCab

iCab

2.9.8

References

Credit

  • Karol Wiesek - iDEFENSE
  • Greg MacManus - iDEFENSE Labs


Direct URL: http://osvdb.org/36218