Demarc Security Update Advisory

From: Demarc Security Support (supportat_private)
Date: Tue Apr 16 2002 - 17:15:26 PDT

  • Next message: N|ghtHawk: "Re: Possible vulnerabilities of ICQ files opened in IE or OE"

    ________________________________________________________________________
    
                     Demarc Security Update Advisory
    ________________________________________________________________________
    
    Subject:                1.05 login bypass advisory
    Date:                   16 April, 2002
    ________________________________________________________________________
    
    Earlier today we were informed indirectly via a bugtraq posting, of a
    security issue in the 1.05 version of our software. While were already
    scheduled to release version 1.6 of the software tomorrow, it is advised
    that you apply the following official patch to your current installation.
    On untrusted networks, the bug could lead to acquisition of
    administrative privileges within the Console.
    
    ---------
    
    --- demarc              Sun Nov 11 23:48:39 2001
    +++ demarc-patched      Tue Apr 16 12:49:56 2002
    @@ -6094,6 +6094,7 @@
     ################
     sub check_login{
     my ($session_id) = @_;
    +$session_id=~tr/[a-zA-Z0-9]//dc;
    
     ($session_id) || return;
     &expire_sessions;
    
    ----------
    
    This bug is not an issue with version 1.6 which is scheduled for
    release on Wednesday 17 April, 2002.  Please visit the new web site,
    which will also be launched tomorrow, to download this new version.
    
    If you have any questions related to this bug, please email us at
    supportat_private
    



    This archive was generated by hypermail 2b30 : Tue Apr 16 2002 - 22:52:40 PDT