Multiple Vendor FTPD realpath Vulnerability
BID:113
Info
Multiple Vendor FTPD realpath Vulnerability
| Bugtraq ID: | 113 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 1999 12:00AM |
| Updated: | Feb 09 1999 12:00AM |
| Credit: | This vulnerability was first posted to the Bugtraq mailing list by Jordan Ritter of Netect on February 9/1999. |
| Vulnerable: |
Washington University wu-ftpd 2.4.2 academ[BETA-18] Washington University wu-ftpd 2.4.2 (beta 18) VR9 Slackware Linux 3.6 Slackware Linux 3.5 Slackware Linux 3.4 SCO Unixware 7.0.1 SCO Unixware 7.0 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0 Redhat wu-ftpd 2.4.2 b18-2 Redhat Linux 5.1 Redhat Linux 5.0 ProFTPD Project ProFTPD 1.2 pre1 Debian Linux 2.0 Caldera OpenLinux 1.3 |
| Not Vulnerable: |
Washington University wu-ftpd 2.4.2 (beta 18) VR10 SCO Open Desktop 3.0 SCO CMW+ 3.0 Redhat wu-ftpd 2.4.2 b18-2.1 NcFTP Software NcFTPD 2.3.5 IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.9 HP HP-UX 10.8 Debian proftpd 1.2 pre1-2 BeroFTPD BeroFTPD 1.2 |
Discussion
Multiple Vendor FTPD realpath Vulnerability
There is a vulnerability in ProFTPD versions 1.2.0pre1 and earlier and in wu-ftpd 2.4.2 (beta 18) VR9 and earlier. This vulnerability is a buffer overflow triggered by unusually long path names (directory structures). For example, if a user has write privilages he or she may create an unusually long pathname which due to insuficient bounds checking in ProFTPD will overwrite the stack. This will allow the attacker to insert their own instruction set on the stack to be excuted thereby elavating their access.
The problem is in a bad implementation of the "realpath" function.
There is a vulnerability in ProFTPD versions 1.2.0pre1 and earlier and in wu-ftpd 2.4.2 (beta 18) VR9 and earlier. This vulnerability is a buffer overflow triggered by unusually long path names (directory structures). For example, if a user has write privilages he or she may create an unusually long pathname which due to insuficient bounds checking in ProFTPD will overwrite the stack. This will allow the attacker to insert their own instruction set on the stack to be excuted thereby elavating their access.
The problem is in a bad implementation of the "realpath" function.
Exploit / POC
Multiple Vendor FTPD realpath Vulnerability
x
x
Solution / Fix
Multiple Vendor FTPD realpath Vulnerability
Solution:
Professional FTP
-----------------------
ProFTPd 1.2.0pre2 is available from ftp://ftp.proftpd.org/distrib/
Debian GNU/Linux 2.0 alias hamm
------------------------------------------------
This version of Debian was released only for the Intel and the Motorola 680x0 architecture.
Source archives: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1.orig.tar.gz
MD5 checksum: 40695cf2ce6a7ff70e36e2c4d140a50e ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.diff.gz
MD5 checksum: b9709fc768ba863bef08729325a9c53a ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.dsc
MD5 checksum: a2245a4681873caad9dd83002e653bb0
Intel architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_i386.deb
checksum: 6fa9921e694972015d4e3d34184c4f2b
Motorola 680x0 architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_m68k.
MD5 checksum: 52053f8b9f348ff1929db91951cf394f
Solution:
Professional FTP
-----------------------
ProFTPd 1.2.0pre2 is available from ftp://ftp.proftpd.org/distrib/
Debian GNU/Linux 2.0 alias hamm
------------------------------------------------
This version of Debian was released only for the Intel and the Motorola 680x0 architecture.
Source archives: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1.orig.tar.gz
MD5 checksum: 40695cf2ce6a7ff70e36e2c4d140a50e ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.diff.gz
MD5 checksum: b9709fc768ba863bef08729325a9c53a ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.dsc
MD5 checksum: a2245a4681873caad9dd83002e653bb0
Intel architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_i386.deb
checksum: 6fa9921e694972015d4e3d34184c4f2b
Motorola 680x0 architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_m68k.
MD5 checksum: 52053f8b9f348ff1929db91951cf394f
References
Multiple Vendor FTPD realpath Vulnerability
References:
References:
- Debian FTP packages: Buffer overflow in some ftp servers (Debian GNU/Linux)
- Netect Discovers Threatening FTP Server Vulnerability (Netect)