rejetto forum

Rejetto HTTP File Server (HFS) search feature fails to handle null bytes

0 Members and 1 Guest are viewing this topic.

Offline elektroinside

  • Occasional poster
  • *
    • Posts: 1
    • View Profile
Hi,

If this has been mentioned before, sorry.

I just found this: http://www.kb.cert.org/vuls/id/251276

Description
CWE-158: Improper Neutralization of Null Byte or NUL Character - CVE-2014-6287
Rejetto HFS versions 2.3, 2.3a, and 2.3b are vulnerable to remote command execution due to a regular expression in parserLib.pas that fails to handle null bytes. Commands that follow a null byte in the search string are executed on the host system.

Might be something to fix though, as i just restarted the entire windows machine with this one...

Thanks!


Offline xpl01t

  • Occasional poster
  • *
    • Posts: 16
    • View Profile
Thanks for your report, by the way this vulnerability was already fixed in the last version


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13510
    • View Profile