CVE-2005-2848: Medium severity Barracuda Networks Barracuda Spam Firewall vulnerability
Published Sep 8, 2005
·Updated
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
Affected Software
2 affected components
Barracuda Networks Barracuda Spam Firewall=3.1.16
Barracuda Networks Barracuda Spam Firewall=3.1.17
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 8, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2848?
CVE-2005-2848 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2005-2848?
To mitigate CVE-2005-2848, upgrade the Barracuda Spam Firewall to firmware versions 3.1.18 or later.
3
What systems are affected by CVE-2005-2848?
CVE-2005-2848 affects Barracuda Spam Firewall versions 3.1.16 and 3.1.17.
4
Can CVE-2005-2848 be exploited remotely?
Yes, CVE-2005-2848 can be exploited remotely by attackers using a specially crafted request.
5
What type of attack does CVE-2005-2848 enable?
CVE-2005-2848 enables directory traversal attacks, allowing attackers to read arbitrary files on the server.