Closed GoogleCodeExporter closed 8 years ago
Update from Kaspersky:
Hi Tavis,
Thank you for reporting this vulnerability to us! We confirm the bug with
Certificate handling path traversal.
We are working on creating a fix. I’ll let you know our fix plan for the bug
as soon as we align it internally.
Best regards,
Igor
Original comment by tav...@google.com
on 21 Sep 2015 at 9:11
I believe this issue is scheduled to be fixed today, I'm testing it in a VM now.
Original comment by tav...@google.com
on 9 Oct 2015 at 6:13
Final fix was released on November 16th.
Original comment by tav...@google.com
on 16 Nov 2015 at 7:25
Hello Tavis,
If possible can you help me with the following:
How were you able to write a .bat file? I am only able create .cer files.
Including the null character '\x00' in the CommonName does not seem to be
working. What version of Kaspersky was this tested against?
Original comment by athmi...@gmail.com
on 24 Nov 2015 at 5:44
Also it does not look like the path traversal is fixed on the latest version.
Kaspersky is still vulnerable after updating to the latest version.
Original comment by athmi...@gmail.com
on 25 Nov 2015 at 5:08
Original issue reported on code.google.com by
tav...@google.com
on 18 Sep 2015 at 11:13Attachments: