[ic] IMPORTANT: Workaround for IC problem

Mike Heins interchange-users@icdevgroup.org
Mon Aug 12 17:15:02 2002


Quoting Joachim Leidinger (jojo@blackpoint.de):
> Mike Heins wrote:
> > Dear All,
> > 
> > There was a serious security problem found with all versions of
                                               ^^^^^^^^^^^^^^^^^^^^^^
> > Interchange and Minivend. It allows reading of arbitrary files that
    ^^^^^^^^^^^^^^^^^^^^^^^^


> > can be read by the Interchange/Minivend user ID.
> > 
> > There is a workaround that is immediately effective:
> > 
> > * Move or remove the "doc" directory, if it exists in the Interchange
> >   software directory.
> ...
> Question:
> Is there a problem with all version of IC? And with MV too?
> 

As was said.

-- 
Mike Heins
Perusion -- Expert Interchange Consulting    http://www.perusion.com/
phone +1.513.523.7621      <mike@perusion.com>

I have a cop friend who thinks he ought be able to give a new ticket;
"too dumb for conditions".