[CVE-2008-0252] Directory traversal vulnerability allows modification of arbitrary files
Bug #187481 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cherrypy3 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Edgy |
Invalid
|
Undecided
|
Unassigned | ||
Feisty |
Invalid
|
Undecided
|
Unassigned | ||
Gutsy |
Fix Released
|
High
|
William Grant | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned | ||
python-cherrypy (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Edgy |
Fix Released
|
High
|
William Grant | ||
Feisty |
Fix Released
|
High
|
William Grant | ||
Gutsy |
Fix Released
|
High
|
William Grant | ||
Hardy |
Fix Released
|
High
|
Unassigned |
Bug Description
Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/
All python-cherrypy and cherrypy3 releases are affected, except for cherrypy3/hardy.
Changed in cherrypy3: | |
assignee: | nobody → fujitsu |
status: | Triaged → In Progress |
Changed in python-cherrypy: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
2.0 (in Dapper) is very different, and doesn't seem vulnerable. cherrypy3 also doesn't exist in Edgy/Feisty. Thanks LP.