Actions
Bug #16412
closedPotential file enumeration vulnerability in the Snort package via IP reputation lists
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:
Description
There is a potential file enumeration vulnerability in the Snort package:
In /usr/local/www/snort/snort_ip_reputation.php
, the value of the iplist
parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists.
Reported by Alex Williams of Pellera Technology via VulnCheck, CVE-2025-34173
Updated by Jim Pingle 3 days ago
- Status changed from New to Resolved
- % Done changed from 0 to 100
MR Merged
Updated by Jim Pingle 3 days ago
- Private changed from Yes to No
New package build is now published and available for Plus 25.07.1, Plus 25.07, CE 2.8.1, and CE 2.8.0.
Actions