The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.
Link | Tags |
---|---|
http://osvdb.org/33369 | vdb entry |
http://www.securityfocus.com/archive/1/455977/100/0/threaded | mailing list |