CVE-2011-1595
published 2011-05-24CVE-2011-1595: Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers…
PriorityP425medium4.3CVSS 2.0
AVAACHAuNCPIPAP
EPSS
1.09%
62.1th percentile
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rdesktop | < rdesktop 1.7.0-1 (bookworm) | rdesktop 1.7.0-1 (bookworm) |
| rdesktop | rdesktop | <= 1.6.0 | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | >= 0 < 1.7.0-1 | 1.7.0-1 |
| rdesktop | rdesktop | >= 0 < 1.7.0-1 | 1.7.0-1 |
| rdesktop | rdesktop | >= 0 < 1.7.0-1 | 1.7.0-1 |
| rdesktop | rdesktop | >= 0 < 1.7.0-1 | 1.7.0-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:A/AC:H/Au:N/C:P/I:P/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rdesktop vulnerability
vendor_ubuntu·2011-05-25
CVE-2011-1595 rdesktop vulnerability
Title: rdesktop vulnerability
Summary: An attacker could access your files if rdesktop connected to a malicious
server.
It was discovered that rdesktop incorrectly handled specially crafted
paths when using disk redirection. If a user were tricked into connecting
to a malicious server, an attacker could access arbitrary files on the
user's filesystem.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rdesktop remote file access
vendor_redhat·2011-04-18·CVSS 4.3
CVE-2011-1595 [MEDIUM] rdesktop remote file access
rdesktop remote file access
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
Debian
CVE-2011-1595: rdesktop - Directory traversal vulnerability in the disk_create function in disk.c in rdesk...
vendor_debian·2011·CVSS 4.3
CVE-2011-1595 [MEDIUM] CVE-2011-1595: rdesktop - Directory traversal vulnerability in the disk_create function in disk.c in rdesk...
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
Scope: local
bookworm: resolved (fixed in 1.7.0-1)
bullseye: resolved (fixed in 1.7.0-1)
forky: resolved (fixed in 1.7.0-1)
sid: resolved (fixed in 1.7.0-1)
trixie: resolved (fixed in 1.7.0-1)
GHSA
GHSA-x8vw-2wrg-9c52: Directory traversal vulnerability in the disk_create function in disk
ghsa_unreviewed·2022-05-17
CVE-2011-1595 [MEDIUM] CWE-22 GHSA-x8vw-2wrg-9c52: Directory traversal vulnerability in the disk_create function in disk
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
OSV
CVE-2011-1595: Directory traversal vulnerability in the disk_create function in disk
osv·2011-05-24·CVSS 4.3
CVE-2011-1595 [MEDIUM] CVE-2011-1595: Directory traversal vulnerability in the disk_create function in disk
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1595 rdesktop remote file access [fedora-all]
bugzilla·2011-04-20·CVSS 4.3
CVE-2011-1595 [MEDIUM] CVE-2011-1595 rdesktop remote file access [fedora-all]
CVE-2011-1595 rdesktop remote file access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676252
Please note: this issue affects multiple supported versions
Bugzilla
CVE-2011-1595 rdesktop remote file access
bugzilla·2011-02-09·CVSS 4.3
CVE-2011-1595 [MEDIUM] CVE-2011-1595 rdesktop remote file access
CVE-2011-1595 rdesktop remote file access
Hi, we (Cendio) have been shared information about a security vulnerability
and have verified it in code that this is possible.
We don't have time to investigate further nor producing a patch and want
some help on that point.
Report:
"The vulnerability is a Directory Traversal vulnerability which affects
an rDesktop client (I believe other products that use the same code will
have the same issue), which will allow someone connecting to a
compromised server (RDP server) or via a MITM vulnerability to access
any file he desires on the user's computer.
The vulnerability allows writing, reading and listing the content of the
directories, all transparently.
The vulnerability requires the user to share "something" on his end
(rDesktop end), and fro
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061170.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061316.htmlhttp://rdesktop.svn.sourceforge.net/viewvc/rdesktop?view=revision&revision=1626http://secunia.com/advisories/44881http://secunia.com/advisories/51023http://security.gentoo.org/glsa/glsa-201210-03.xmlhttp://securitytracker.com/id?1025525http://sourceforge.net/mailarchive/message.php?msg_id=27376554http://sourceforge.net/projects/rdesktop/files/rdesktop/1.7.0/rdesktop-1.7.0.tar.gz/downloadhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:102http://www.securityfocus.com/bid/47419http://www.ubuntu.com/usn/USN-1136-1https://bugzilla.redhat.com/show_bug.cgi?id=676252https://rhn.redhat.com/errata/RHSA-2011-0506.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061170.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061316.htmlhttp://rdesktop.svn.sourceforge.net/viewvc/rdesktop?view=revision&revision=1626http://secunia.com/advisories/44881http://secunia.com/advisories/51023http://security.gentoo.org/glsa/glsa-201210-03.xmlhttp://securitytracker.com/id?1025525http://sourceforge.net/mailarchive/message.php?msg_id=27376554http://sourceforge.net/projects/rdesktop/files/rdesktop/1.7.0/rdesktop-1.7.0.tar.gz/downloadhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:102http://www.securityfocus.com/bid/47419http://www.ubuntu.com/usn/USN-1136-1https://bugzilla.redhat.com/show_bug.cgi?id=676252https://rhn.redhat.com/errata/RHSA-2011-0506.html
2011-05-24
Published