CVE-2013-3706Path Traversal in Zenworks Configuration Management

Severity
5.0MEDIUMNVD
EPSS
50.5%
top 2.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 17

Description

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pg6v-35j6-x9ww: Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 112022-05-17
CVEList
CVE-2013-3706: Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 112014-03-06

📋Vendor Advisories

1
Red Hat
glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)2016-04-27

💬Community

1
Bugzilla
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)2016-04-27
CVE-2013-3706 — Path Traversal | cvebase