Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 101217 - net-analyzer/metasploit: MSFWeb Defanged Mode Restriction Bypass Vulnerability
Summary: net-analyzer/metasploit: MSFWeb Defanged Mode Restriction Bypass Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://securityfocus.com/bid/14455
Whiteboard: B2? [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-08-03 09:04 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-09-02 02:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-08-03 09:04:11 UTC
Metasploit Framework is susceptible to a restriction bypass vulnerability in 
msfweb. This issue is due to a failure of the application to properly implement 
access control restrictions.

This issue allows remote attackers to bypass security restrictions in the 
affected Web server. Attackers may exploit this issue to attack arbitrary 
computers using the Metasploit Framework, while originating the attacks from 
the computer hosting the vulnerable msfweb process.

Attackers may also interact with the payload features in the Metasploit 
Framework to manipulate files on the hosting computer, likely leading to 
executing arbitrary commands and then complete system compromise.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-08-04 08:30:19 UTC
Now that's funny.

netmon : I guess we need to wait for a full release anyway ?
See http://www.metasploit.com/archive/framework/msg00469.html
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-08-10 01:46:26 UTC
The fix is available through msfupdate and has been included in the 2.4 snapshots.
Not sure how we can push a GLSA on this though, we probably need a fixed "version".
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-08-29 07:18:38 UTC
I am tempted to close this one as INVALID, please comment if you think I shouldn't.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-09-02 02:38:30 UTC
Fixed in metasploit update. Won't issue a GLSA about an hole in a exploit
framework. Feel free to reopen if you disagree.