Multiple Vendor FTPD realpath Vulnerability

BID:113

Info

Multiple Vendor FTPD realpath Vulnerability

Bugtraq ID: 113
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Feb 09 1999 12:00AM
Updated: Feb 09 1999 12:00AM
Credit: This vulnerability was first posted to the Bugtraq mailing list by Jordan Ritter of Netect on February 9/1999.
Vulnerable: Washington University wu-ftpd 2.4.2 academ[BETA-18]
+ Redhat Linux 5.2 i386
Washington University wu-ftpd 2.4.2 (beta 18) VR9
Slackware Linux 3.6
Slackware Linux 3.5
Slackware Linux 3.4
SCO Unixware 7.0.1
SCO Unixware 7.0
SCO Open Server 5.0.5
SCO Open Server 5.0.4
SCO Open Server 5.0.3
SCO Open Server 5.0.2
SCO Open Server 5.0
Redhat wu-ftpd 2.4.2 b18-2
+ Redhat Linux 5.2 i386
Redhat Linux 5.1
- Standard & Poors ComStock 4.2.4
Redhat Linux 5.0
ProFTPD Project ProFTPD 1.2 pre1
Debian Linux 2.0
Caldera OpenLinux 1.3
Not Vulnerable: Washington University wu-ftpd 2.4.2 (beta 18) VR10
SCO Open Desktop 3.0
SCO CMW+ 3.0
Redhat wu-ftpd 2.4.2 b18-2.1
NcFTP Software NcFTPD 2.3.5
IBM AIX 4.3
IBM AIX 4.2.1
IBM AIX 4.2
IBM AIX 4.1.5
IBM AIX 4.1.4
IBM AIX 4.1.3
IBM AIX 4.1.2
IBM AIX 4.1.1
IBM AIX 4.1
HP HP-UX 11.0
HP HP-UX 10.20
HP HP-UX 10.9
HP HP-UX 10.8
Debian proftpd 1.2 pre1-2
BeroFTPD BeroFTPD 1.2

Discussion

Multiple Vendor FTPD realpath Vulnerability

There is a vulnerability in ProFTPD versions 1.2.0pre1 and earlier and in wu-ftpd 2.4.2 (beta 18) VR9 and earlier. This vulnerability is a buffer overflow triggered by unusually long path names (directory structures). For example, if a user has write privilages he or she may create an unusually long pathname which due to insuficient bounds checking in ProFTPD will overwrite the stack. This will allow the attacker to insert their own instruction set on the stack to be excuted thereby elavating their access.

The problem is in a bad implementation of the "realpath" function.

Exploit / POC

Solution / Fix

Multiple Vendor FTPD realpath Vulnerability

Solution:
Professional FTP
-----------------------

ProFTPd 1.2.0pre2 is available from ftp://ftp.proftpd.org/distrib/

Debian GNU/Linux 2.0 alias hamm
------------------------------------------------

This version of Debian was released only for the Intel and the Motorola 680x0 architecture.

Source archives: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1.orig.tar.gz
MD5 checksum: 40695cf2ce6a7ff70e36e2c4d140a50e ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.diff.gz
MD5 checksum: b9709fc768ba863bef08729325a9c53a ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2.dsc
MD5 checksum: a2245a4681873caad9dd83002e653bb0

Intel architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_i386.deb
checksum: 6fa9921e694972015d4e3d34184c4f2b

Motorola 680x0 architecture: ftp://ftp.debian.org/debian/dists/proposed-updates/proftpd_1.2.0pre1-2_m68k.
MD5 checksum: 52053f8b9f348ff1929db91951cf394f

References

Multiple Vendor FTPD realpath Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report