[NT] Kyocera Mita Scanner File Utility (Multiple)

SecuriTeam <[email protected]> 29 Aug 2008 11:47:36 +0200
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Kyocera Mita Scanner File Utility (Multiple)
------------------------------------------------------------------------


SUMMARY

Kyocera Mita multifunction devices come with the ability to scan to the 
user's desktop. Part of the solution requires a listener at the PC/Mac, 
which handles authorization and document upload. This listener has several 
logic bugs and, as a result, the authorization can be bypassed, files can 
be uploaded, auditing can be spoofed, and the storage location can be 
altered from the configured value.

DETAILS

Vulnerable Systems:
 * Kyocera Mita Scanner File Utility version 3.3.0.1

Unauthorized document upload - The listener works in conjunction with the 
multifunction device to authorize the user. If an attacker connects direct 
to the listener with a custom program, all authorization can be bypassed. 
This provides an attacker with the ability to directly upload a file to 
the target's computer.

File Redirection - During the transfer process, the file name is provided 
to the listener. This name can be altered to include "../", which causes 
the listener to break out of the specified file storage location and 
allows an attacker to upload a file anywhere on the target system.

Upload any file type - There are no checks in the listener to validate the 
content of the uploaded file. As a result, an attacker can upload any file 
type with any file name. When combined with the other bugs, this give the 
attacker the ability to overwrite existing files, or write a binary into 
the Startup Folder.

MetaSploit module is located at:
 <http://www.whitewolfsecurity.com/security/metasploit/fileutility.txt> 
http://www.whitewolfsecurity.com/security/metasploit/fileutility.txt

Vendor Response:
Vendor has released an update that fixes only the file redirection issue.


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> 
Seth Fogie.
The original article can be found at:  
<http://www.informit.com/guides/content.aspx?g=security&seqNum=320> 
http://www.informit.com/guides/content.aspx?g=security&seqNum=320 and  
<http://www.informit.com/guides/content.aspx?g=security&seqNum=321> 
http://www.informit.com/guides/content.aspx?g=security&seqNum=321



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.