IglooFTP Server Response Download Filename File Corruption Vulnerability
BID:11960
Info
IglooFTP Server Response Download Filename File Corruption Vulnerability
| Bugtraq ID: | 11960 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Yosef Klein. |
| Vulnerable: |
IglooFTP IglooFTP 0.6.1 |
| Not Vulnerable: | |
Discussion
IglooFTP Server Response Download Filename File Corruption Vulnerability
IglooFTP does not properly sanitize server-supplied filenames during downloads, potentially allowing for files to be created or overwritten in the context of the client user. This issue is reported to occur when the FTP client is used to recursively download files from a remote FTP server.
This issue reportedly exists in UNIX/Linux based versions of IglooFTP. It is not known if Windows versions are affected.
IglooFTP does not properly sanitize server-supplied filenames during downloads, potentially allowing for files to be created or overwritten in the context of the client user. This issue is reported to occur when the FTP client is used to recursively download files from a remote FTP server.
This issue reportedly exists in UNIX/Linux based versions of IglooFTP. It is not known if Windows versions are affected.
Exploit / POC
IglooFTP Server Response Download Filename File Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IglooFTP Server Response Download Filename File Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IglooFTP Server Response Download Filename File Corruption Vulnerability
References:
References:
- [remote] [control] IglooFTP 0.6.1 does not check for directory escapes ("D. J. Bernstein"
) - IglooFTP Homepage (IglooFTP)