PT-2025-7067 · Unknown · Zoo-Project
Xbow-Security
·
Published
2025-02-18
·
Updated
2025-02-18
·
CVE-2025-25284
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
ZOO-Project (affected versions not specified)
Description:
A vulnerability in the ZOO-Project's WPS implementation allows unauthorized access to files outside the intended directory through path traversal. Specifically, the Gdal Translate service, when processing VRT files, does not properly validate file paths referenced in the VRTRasterBand element, allowing attackers to read arbitrary files on the system. The vulnerability exists because the service doesn't properly sanitize the
SourceFilename parameter in VRT files, allowing relative path traversal sequences (../). This allows reading arbitrary files as raw binary data and converting them to TIFF format, effectively exposing their contents. An unauthenticated attacker can read arbitrary files from the system through path traversal, potentially accessing sensitive information such as configuration files, credentials, or other confidential data stored on the server.Recommendations:
To resolve the issue, all users are advised to upgrade to a version that includes the fix, as committed in
5f155a8. As a temporary workaround, consider restricting access to the Gdal Translate service until the update is applied. Additionally, avoid using the SourceFilename parameter in VRT files until the issue is resolved. There are no known workarounds for this vulnerability.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoo-Project