[15909] in bugtraq

home help back first fref pref prev next nref lref last post

Roxen security alert: Problems with URLs containing null

daemon@ATHENA.MIT.EDU (Peter Bortas)
Sat Jul 22 18:31:16 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <76r98nc4m9.fsf@rimmer.idonex.se>
Date:         Sat, 22 Jul 2000 03:53:34 +0200
Reply-To: Peter Bortas <peter@IDONEX.SE>
From: Peter Bortas <peter@IDONEX.SE>
To: BUGTRAQ@SECURITYFOCUS.COM

Roxen 2.0 up to version 2.0.68 has a vulnerability where using URLs
containing null characters can gain the browser access to information
he is not authorized to:


  * Directory listings in directories with index files
  * In normal filesystems: the sourcecode for RXML files, Pike
    scripts, CGIs etc.
  * information protected by .htaccess files might be revealed under
    special circumstances

Systems Affected

  All Roxen 2.0 releases before 2.0.69. We have been unable to
  reproduce the problem with Roxen 1.3, but this is not fully analyzed
  yet, so it is suggested that a patch is applied as a precaution.

  Roxen SiteBuilder is ONLY affected by the directory listing
  vulnerability.

Solution

  An update package labeled 'Fix for "%00" vulnerability' is available
  from the Roxen 2.0 update server. Use the administration interface
  to download and install this fix. Note that the server needs to be
  restarted when the fix is installed.

  A patch for Roxen 1.3.122 (the latest 1.3 release) is a available as
  ftp://ftp.roxen.com/pub/roxen/patches/roxen_1.3.122-http.pike.patch
  and should be applied to server/protocols/http.pike.

  The Roxen 2.0 upgrade package is also available as a patch if the
  update server can not be used for some reason:
  ftp://ftp.roxen.com/pub/roxen/patches/roxen_2.0.50-http.pike.patch

Credits

  Problem originally reported by <zorgon@sdf.lonestar.org>
  Further comments on the problem by Elias Levy <aleph1@underground.org>

--
Peter Bortas                   http://peter.bortas.org
Roxen IS                       http://www.roxen.com

home help back first fref pref prev next nref lref last post