The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.
References
Configurations
History
21 Nov 2024, 00:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/42719 - | |
References | () http://secunia.com/advisories/29221 - Vendor Advisory | |
References | () http://www.informit.com/articles/article.aspx?p=1177111&seqNum=2 - | |
References | () http://www.securityfocus.com/archive/1/489045/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/28085 - |
Information
Published : 2009-09-01 16:30
Updated : 2024-11-21 00:58
NVD link : CVE-2008-7138
Mitre link : CVE-2008-7138
CVE.ORG link : CVE-2008-7138
JSON object : View
Products Affected
eye.fi
- eye-fi_manager
CWE
CWE-310
Cryptographic Issues