CVE-2011-1595 - CERT CVE
ID CVE-2011-1595
Sažetak Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
Reference
CVSS
Base: 4.3
Impact: 6.4
Exploitability:3.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL PARTIAL
CVSS vektor AV:A/AC:H/Au:N/C:P/I:P/A:P
Zadnje važnije ažuriranje 05-04-2013 - 03:01
Objavljeno 24-05-2011 - 23:55