First published: Fri Feb 20 2009(Updated: )
Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | <=8.80.1.1 | |
Ivanti LANDESK Management Suite | =8.7 | |
Ivanti LANDESK Management Suite | =8.7-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6195 is considered a high severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2008-6195, upgrade your LANDesk Management Suite to version 8.80.1.2 or later.
CVE-2008-6195 affects LANDesk Management Suite versions 8.80.1.1 and earlier, including specific versions like 8.7 and 8.7 SP5.
CVE-2008-6195 allows remote attackers to exploit directory traversal to read arbitrary files on the server.
CVE-2008-6195 is a distinct vulnerability and should not be confused with CVE-2008-1643.