4D WebStar Remote FTP Buffer Overflow Vulnerability
BID:10720
Info
4D WebStar Remote FTP Buffer Overflow Vulnerability
| Bugtraq ID: | 10720 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2004 12:00AM |
| Updated: | Jul 13 2004 12:00AM |
| Credit: | This issue was discovered by @stake Inc. |
| Vulnerable: |
4D WebSTAR 5.3.2 4D WebSTAR 5.3.1 4D WebSTAR 5.3 4D WebSTAR 5.2.4 4D WebSTAR 5.2.3 4D WebSTAR 5.2.2 4D WebSTAR 5.2.1 4D WebSTAR 5.2 4D WebSTAR 4.0 |
| Not Vulnerable: |
4D WebSTAR 5.3.3 |
Discussion
4D WebStar Remote FTP Buffer Overflow Vulnerability
It is reported that 4D WebStar is affected by a remote, pre-authentication FTP buffer overflow vulnerability. This issue is due to a failure of the application to properly verify buffer boundaries when storing user supplied input into internal, static buffers.
Successful exploitation will allow attackers to execute arbitrary code in the context of the affected application; the application typically runs as the user 'webstar' in group 'wheel'. This issue may also trigger a denial of service condition in the affected service.
It is reported that 4D WebStar is affected by a remote, pre-authentication FTP buffer overflow vulnerability. This issue is due to a failure of the application to properly verify buffer boundaries when storing user supplied input into internal, static buffers.
Successful exploitation will allow attackers to execute arbitrary code in the context of the affected application; the application typically runs as the user 'webstar' in group 'wheel'. This issue may also trigger a denial of service condition in the affected service.
Exploit / POC
4D WebStar Remote FTP Buffer Overflow Vulnerability
An exploit has been released as part of the MetaSploit Framework 2.3.
An exploit has been released as part of the MetaSploit Framework 2.3.
Solution / Fix
4D WebStar Remote FTP Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
4D WebSTAR 5.2
4D WebSTAR 5.2.1
4D WebSTAR 5.2.2
4D WebSTAR 5.2.3
4D WebSTAR 5.2.4
4D WebSTAR 5.3
4D WebSTAR 5.3.1
4D WebSTAR 5.3.2
Solution:
The vendor has released an upgrade dealing with this issue.
4D WebSTAR 5.2
4D WebSTAR 5.2.1
4D WebSTAR 5.2.2
4D WebSTAR 5.2.3
4D WebSTAR 5.2.4
4D WebSTAR 5.3
4D WebSTAR 5.3.1
4D WebSTAR 5.3.2
References
4D WebStar Remote FTP Buffer Overflow Vulnerability
References:
References:
- 4D Inc. Homepage (4D Inc.)
- 4D WebSTAR Product Page (4D Inc.)
- Metasploit Framework Exploits (Metasploit)
- @stake advisory: WebSTAR (5.3.2 and below) Multiple Vulnerabilities (@stake)