CVE-2008-2439: Path Traversal
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business Security 5.0 before build 1220 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP request. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2439?
CVE-2008-2439 has a moderate severity level due to its potential for directory traversal attacks.
How do I fix CVE-2008-2439?
To fix CVE-2008-2439, upgrade to the patched version of Trend Micro OfficeScan or Worry-Free Business Security that addresses this vulnerability.
What software versions are affected by CVE-2008-2439?
CVE-2008-2439 affects Trend Micro OfficeScan versions 7.3 and 8.0 SP1, as well as Worry-Free Business Security 5.0.
Can CVE-2008-2439 lead to unauthorized access?
Yes, CVE-2008-2439 can potentially allow an attacker to access unauthorized directories on the system.
Is there a known exploit for CVE-2008-2439?
There are known exploits for CVE-2008-2439 that take advantage of the directory traversal vulnerability.