PT-2013-4885 · Xymon+1 · Xymon+1

Cleaver

·

Published

2013-08-11

·

Updated

2014-01-23

·

CVE-2013-4173

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Xymon versions prior to 4.3.12
Description A directory traversal issue exists in the trend-data daemon (xymond rrd) of Xymon, allowing remote attackers to delete arbitrary files by including a .. (dot dot) in the host name within a "drophost" command.
Recommendations For versions prior to 4.3.12, update to version 4.3.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the "drophost" command to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1080
CVE-2013-4173
MGASA-2013-0243

Affected Products

Alt Linux
Xymon