Update Protection against VWar Remote File Inclusion Vulnerability
| Check Point Reference: | CPAI-2006-077 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | FrSIRT/ADV-2006-1228 |
|
| Industry Reference(s): | CVE-2006-1636 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Virtual War version 1.5.0-R12 and prior | ||
| Vulnerability Description Several vulnerabilities have been reported in Virtual War (VWar) due to input validation errors in several scripts. Remote attackers could exploit these vulnerabilities to include malicious files and compromise a vulnerable system. |
||
|
Update/Patch Available Upgrade to Virtual War version 1.5.0-R13 : http://www.vwar.de/download.php |
|
|
Vulnerability Details These flaws are due to input validation errors in the "includes/get_header.php", "includes/functions_common.php" and "includes/functions_front.php" scripts that do not validate the "vwar_root" variable. |
Protection Overview
The Update enables the HTTP Worm Catcher to detect and block the vulnerability based on a pre-defined worm signature.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on July 5, 2006 includes the following protections:
Malformed SSH Init Message Protection (CPAI-2006-069)
Multiple IMAP Servers Directory Traversal Protection (CPAI-2006-070)
VNC Authentication Bypass Protection (CPAI-2006-071)
COM Object Instantiation Protection (MS06-013) - CPAI-2006-072
COM Object Instantiation Memory Corruption Vulnerability (MS06-021) - CPAI-2006-073
Microsoft JScript Remote Code Execution Protection (MS06-023) - CPAI-2006-074
Symantec Sygate SQL Injection Protection (CPAI-2006-075)
Horde Help Viewer Protection (CPAI-2006-076)
Virtual War (VWar) File Inclusion Protection (CPAI-2006-077)
AWStats Remote Command Execution Protection - CPAI-2006-078
Windows Media Player PNG Protection (MS06-024) - CPAI-2006-079
ART Image Rendering Protection (MS06-022) - CPAI-2006-080
MySQL Server str_to_date DoS Protection (CPAI-2006-081)
Enhanced Protection against AWStats "migrate" Shell Command Injection (CPAI-2006-053)
Additional Logs added to the FTP patterns engine (CPAI-2006-040)