JFTPGW Remote Syslog Format String Vulnerability
BID:10438
Info
JFTPGW Remote Syslog Format String Vulnerability
| Bugtraq ID: | 10438 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0448 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
jftpgw jftpgw 0.13.3 jftpgw jftpgw 0.13.2 jftpgw jftpgw 0.13.1 jftpgw jftpgw 0.13 |
| Not Vulnerable: |
jftpgw jftpgw 0.13.4 |
Discussion
JFTPGW Remote Syslog Format String Vulnerability
jftpgw FTP proxy is prone to a remotely exploitable format string vulnerability.
This issue could be exploited to execute arbitrary code in the context of the process, which is usually run as nobody (or an equivalent user). This is due to insecure usage of the syslog() function.
jftpgw FTP proxy is prone to a remotely exploitable format string vulnerability.
This issue could be exploited to execute arbitrary code in the context of the process, which is usually run as nobody (or an equivalent user). This is due to insecure usage of the syslog() function.
Exploit / POC
JFTPGW Remote Syslog Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
JFTPGW Remote Syslog Format String Vulnerability
Solution:
Please see Debian advisory DSA 510-1 to details on how to obtain fixes to address the issue.
OpenBSD includes the software in their ports collection. OpenBSD has updated the port to version 0.13.5 in CVS.
The vendor released jftpgw 0.13.4 to address this issue.
jftpgw jftpgw 0.13
jftpgw jftpgw 0.13.1
jftpgw jftpgw 0.13.2
jftpgw jftpgw 0.13.3
Solution:
Please see Debian advisory DSA 510-1 to details on how to obtain fixes to address the issue.
OpenBSD includes the software in their ports collection. OpenBSD has updated the port to version 0.13.5 in CVS.
The vendor released jftpgw 0.13.4 to address this issue.
jftpgw jftpgw 0.13
-
jftpgw jftpgw-0.13.4.tar.gz
http://www.mcknight.de/jftpgw/jftpgw-0.13.4.tar.gz
jftpgw jftpgw 0.13.1
-
Debian jftpgw_0.13.1-1woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_alpha.deb -
Debian jftpgw_0.13.1-1woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_arm.deb -
Debian jftpgw_0.13.1-1woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_hppa.deb -
Debian jftpgw_0.13.1-1woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_i386.deb -
Debian jftpgw_0.13.1-1woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_ia64.deb -
Debian jftpgw_0.13.1-1woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_m68k.deb -
Debian jftpgw_0.13.1-1woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_mips.deb -
Debian jftpgw_0.13.1-1woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_mipsel.deb -
Debian jftpgw_0.13.1-1woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_powerpc.deb -
Debian jftpgw_0.13.1-1woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_s390.deb -
Debian jftpgw_0.13.1-1woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/j/jftpgw/jftpgw_0.13.1-1w oody1_sparc.deb -
jftpgw jftpgw-0.13.4.tar.gz
http://www.mcknight.de/jftpgw/jftpgw-0.13.4.tar.gz
jftpgw jftpgw 0.13.2
-
jftpgw jftpgw-0.13.4.tar.gz
http://www.mcknight.de/jftpgw/jftpgw-0.13.4.tar.gz
jftpgw jftpgw 0.13.3
-
jftpgw jftpgw-0.13.4.tar.gz
http://www.mcknight.de/jftpgw/jftpgw-0.13.4.tar.gz