OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: mark-bugtraqthunderstone.com
Date: Mon Feb 11 2002 - 15:58:10 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ('binary' encoding is not supported, stored as-is) In-Reply-To: <200202060513.g165DiV11177mail10.bigmailbox.com>

    THUNDERSTONE RESPONSE TO SECURITY ALERT

    Thunderstone Software is aware of a report about a
    "vulnerability" in one of our products, published
    on Bugtraq. Thunderstone takes such concerns
    seriously. We offer the following details for
    concerned customers and users of our software.

    Texis issues an error message that reveals a web
    server's "path to document root" and the operating
    system the program was compiled under, if asked to
    execute a script that does not exist. The message
    is intended to aide in solving set-up or
    configuration problems.

    Customers using vhttpd can use an EntryScript to
    check for the existence of a script prior to
    invoking texis, and take an appropriate action if
    the script does not exist.

    A risk is present only if there is some additional
    vulnerability on that same server. The reported
    issue does not provide access to the server,
    although it may be used by an attacker to narrow
    the attack against other vulnerabilities.

    Although we consider the vulnerability minor, we
    have initiated a modification to resolve the
    issue. Customers who wish to take advantage of the
    change should contact Thunderstone tech support.

    Some customers may prefer the current
    functionality, which is not inadvertent or a
    "bug." Rather, Thunderstone designed its software
    to include this information for resolving web
    server path problems, which are common.

    For additional information, please contact
    Thunderstone Software, http://www.thunderstone.com