Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
BID:10271
Info
Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10271 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0430 |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery is credited to @stake, Inc. <www.atstake.com>. |
| Vulnerable: |
Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
It has been reported that AppleFileServer is prone to a remote buffer overflow vulnerability that may allow a remote attacker to execute arbitrary code in order to gain unauthorized access. The issue presents itself when the application receives a 'LoginExt' packet containing a malformed 'PathName' argument.
Apple Mac OS X 10.3.3 and prior are reported to be prone to this issue.
This issue was previously disclosed in a multiple BID 10268 (Apple OS X Multiple Unspecified Large Input Vulnerabilities), however, it is being assigned a new BID as a result of new information available.
It has been reported that AppleFileServer is prone to a remote buffer overflow vulnerability that may allow a remote attacker to execute arbitrary code in order to gain unauthorized access. The issue presents itself when the application receives a 'LoginExt' packet containing a malformed 'PathName' argument.
Apple Mac OS X 10.3.3 and prior are reported to be prone to this issue.
This issue was previously disclosed in a multiple BID 10268 (Apple OS X Multiple Unspecified Large Input Vulnerabilities), however, it is being assigned a new BID as a result of new information available.
Exploit / POC
Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
An Exploit has been released for this issue as part of the Metasploit Framework project version 2.2. Various other exploits have been released as well. Please see the Metasploit exploits site in Web references for more information.
An additional exploit (priv8afp.pl) has been released.
An Exploit has been released for this issue as part of the Metasploit Framework project version 2.2. Various other exploits have been released as well. Please see the Metasploit exploits site in Web references for more information.
An additional exploit (priv8afp.pl) has been released.
Solution / Fix
Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
Solution:
Apple has released security advisory APPLE-SA-2004-05-03 dealing with this and other issues. Please see the referenced advisory for more information.
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3.3
Apple Mac OS X 10.3.3
Solution:
Apple has released security advisory APPLE-SA-2004-05-03 dealing with this and other issues. Please see the referenced advisory for more information.
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X Server 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
References
Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
References:
References:
- Metasploit Framework Exploits (Metasploit)
- @stake: AppleFileServer Remote Command Execution ("@stake Advisories"
)