SB2015031103 - Security restrictions bypass in Aconf



SB2015031103 - Security restrictions bypass in Aconf

Published: March 11, 2015

Security Bulletin ID SB2015031103
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2015-1419)

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to unknown error related to parsing of "deny_file" option. A remote authenticated attacker can bypass certain security restrictions and gain unauthorized access to protected files on the system.

Successful exploitation of the vulnerability may allow an authenticated attacker to bypass intended security restrictions.


Remediation

Install update from vendor's website.