The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).
References
Link Resource
http://www.openwall.com/lists/oss-security/2018/06/03/1 Mailing List Third Party Advisory
https://github.com/tintinweb/pub/tree/master/pocs/cve-2018-10057 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-06-05T21:00:00

Updated: 2018-06-05T20:57:01

Reserved: 2018-04-11T00:00:00


Link: CVE-2018-10057

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-05T21:29:00.867

Modified: 2018-07-27T14:46:42.937


Link: CVE-2018-10057

JSON object: View

cve-icon Redhat Information

No data.

CWE