Executive brief
UMN Gopher is an early internet protocol used for distributing, searching, and retrieving documents. A critical vulnerability in the Gopher server software allows remote attackers to access and read any file on the host system that the server process has permissions to view. This could lead to the exposure of sensitive system files, configuration data, or private user documents.
Technical details
The UMN Gopher and Gopher+ daemons (versions 1.12 and 2.0x) contain a vulnerability that allows for arbitrary file disclosure. By sending specially crafted requests to the Gopher service, a remote, unauthenticated attacker can bypass intended directory restrictions. This allows the attacker to retrieve any file on the filesystem that the Gopher daemon process has read access to. The vulnerability is exploitable over the network without user interaction. While specific technical details on the root cause (e.g., directory traversal or input validation failure) are not explicitly detailed in the legacy record, the impact is a complete compromise of data confidentiality for files accessible by the service account.
Affected products
- University of Minnesota (UMN) gopher 1.12, 2.0x
- University of Minnesota (UMN) gopher+ 1.12, 2.0x
Timeline
- 1993-08-09: advisory: Initial NVD publication date