Description: A vulnerability and a security issue have been reported in IPCop, which can be exploited by malicious people to cause a DoS (Denial of Service), and by malicious, local users to gain access to potentially sensitive information.
1) A vulnerability in Squid may be exploited by malicious people to cause a DoS.
2) The key used to encrypt web backup files is stored in "/var/ipcop/backup/" and is world-readable. This can potentially be exploited by malicious users to decrypt backup files, or by the "nobody" user to overwrite arbitrary files by creating malicious backup files and restoring them.
Note: A race condition that can potentially allow the "nobody" user to replace the backup file before it is encrypted has also been fixed. It is normally not possible to logon as the "nobody" user and this must be exploited in conjunction with some other vulnerability.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.