Unquoted Service Path Considerations

Need new test, action, option? Post request here.
Post Reply
paulnus
Posts: 17
Joined: Mon Aug 29, 2011 12:18 pm

Unquoted Service Path Considerations

Post by paulnus »

We regularly run security scans and often we see that the RMA installs will be vulnerable to an "unquoted service path". I was hoping future releases could consider having protections in place so that when installed using the configuration tool, it will have proper wrapped quotes to prevent potential exploits.

References:
http://www.nessus.org/u?84a4cc1c
http://cwe.mitre.org/data/definitions/428.html
https://www.commonexploits.com/unquoted-service-paths/
http://www.nessus.org/u?4aa6acbc

The resolution would be to ensure double quotes surround the service path in the registry.
KS-Soft
Posts: 12821
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

Thank you for the tip, will be changed in next version

Regards
Alex
KS-Soft
Posts: 12821
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

Done in version 12.60

Regards
Alex
Post Reply