ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
BID:12487
Info
ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
| Bugtraq ID: | 12487 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Feb 08 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Remus Hociota. |
| Vulnerable: |
ArGo Software Design FTP Server 1.4.2 .2 ArGo Software Design FTP Server 1.4.2 .1 ArGo Software Design FTP Server 1.4.2 .0 ArGo Software Design FTP Server 1.4.1 .9 ArGo Software Design FTP Server 1.4.1 .8 ArGo Software Design FTP Server 1.4.1 .7 ArGo Software Design FTP Server 1.4.1 .6 ArGo Software Design FTP Server 1.4.1 .5 ArGo Software Design FTP Server 1.4.1 .4 ArGo Software Design FTP Server 1.4.1 .3 ArGo Software Design FTP Server 1.4.1 .2 ArGo Software Design FTP Server 1.4.1 .1 |
| Not Vulnerable: |
ArGo Software Design FTP Server 1.4.2 .7 |
Discussion
ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
ArGoSoft FTP server is reportedly affected by a vulnerability regarding the upload of compressed shortcut files. This issue is due to the application failing to verify the contents of ZIP files during execution of the 'SITE UNZIP' command. A malicious user with write permission on any directory could extract a shortcut (.lnk) file that points to the directory of their choice.
It is conjectured this issue is related to BID 11589 (ArGoSoft FTP Server Shortcut File Upload Vulnerability) and BID 2961 (ArGoSoft FTP Server .lnk Directory Traversal Vulnerability).
ArGoSoft FTP server is reportedly affected by a vulnerability regarding the upload of compressed shortcut files. This issue is due to the application failing to verify the contents of ZIP files during execution of the 'SITE UNZIP' command. A malicious user with write permission on any directory could extract a shortcut (.lnk) file that points to the directory of their choice.
It is conjectured this issue is related to BID 11589 (ArGoSoft FTP Server Shortcut File Upload Vulnerability) and BID 2961 (ArGoSoft FTP Server .lnk Directory Traversal Vulnerability).
Exploit / POC
ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
Solution:
The vendor has addressed this issue in ArGoSoft FTP server 1.4.2.7.
ArGo Software Design FTP Server 1.4.1 .4
ArGo Software Design FTP Server 1.4.1 .2
ArGo Software Design FTP Server 1.4.1 .8
ArGo Software Design FTP Server 1.4.1 .5
ArGo Software Design FTP Server 1.4.1 .9
ArGo Software Design FTP Server 1.4.1 .6
ArGo Software Design FTP Server 1.4.1 .3
ArGo Software Design FTP Server 1.4.1 .1
ArGo Software Design FTP Server 1.4.1 .7
ArGo Software Design FTP Server 1.4.2 .2
ArGo Software Design FTP Server 1.4.2 .1
ArGo Software Design FTP Server 1.4.2 .0
Solution:
The vendor has addressed this issue in ArGoSoft FTP server 1.4.2.7.
ArGo Software Design FTP Server 1.4.1 .4
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .2
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .8
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .5
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .9
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .6
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .3
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .1
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.1 .7
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .2
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .1
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGo Software Design FTP Server 1.4.2 .0
-
ArGoSoft FTP Server 1.4.2.7
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
References
ArGoSoft FTP Server Shortcut File Extension Filter Bypass Vulnerability
References:
References:
- ArGoSoft FTP Server Change List (ArGoSoft)
- ArGoSoft FTP Server Product Home Page (ArGoSoft)