New User, Welcome!     Login

Virtual File System

FreeBSD Security Advisory FreeBSD-SA-09:14.devfs

I.   Background

The device file system (devfs) provides access to system devices, such as
storage devices and serial ports, via the file system namespace.

VFS is the Virtual File System, which abstracts file system operations in
the kernel from the actual underlying file system.

II.  Problem Description

Due to the interaction between devfs and VFS, a race condition exists

Limited upload directory traversal in HTTP File Server 2.2a / 2.3 beta (build #146)

2) Bug
======


HFS allows the uploading of files to the real folders added to the
Virtual File System.
The problem is that an attacker can upload files outside the
destination folder reaching the root or any other directory on the disk
in which is located the upload folder using the ../ pattern.

Note that uploading must be enabled on the target folder, that the



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!