heise Security - News - Adobe web server wide open

CoU経由

AdobeCGIスクリプトディレクトリトラバーサル脆弱性が発見されたそうです。細工されたURLでファイルを見ることが可能とのこと。

SSLキーやパスワードファイルまで見れるそうです。

One of Adobe web server's CGI scripts contains a critical directory traversal vulnerability which allows access to arbitrary system files. Opening a specially crafted URL in a browser is all that is required to display file contents. Apart from config files it is also possible to view log files, SSL keys and password files. Which key pair the retrievable private SSL key belongs to remains to be established; so far it does not seem to correspond to any of the known Adobe SSL certificates.