WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
BID:2644
Info
WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
| Bugtraq ID: | 2644 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2001 12:00AM |
| Updated: | Apr 22 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Len Budney <[email protected]> on April 23, 2001. |
| Vulnerable: |
Texas Imperial Software WFTPD 3.0 0R4 Pro Texas Imperial Software WFTPD 3.0 0R4 |
| Not Vulnerable: |
Texas Imperial Software WFTPD 3.0 0R5 Pro Texas Imperial Software WFTPD 3.0 0R5 |
Discussion
WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
Invalid long strings submitted using either 'RETR' or 'CWD' commands to a host running WFTPD server, will result in the service terminating due to a buffer overflow. It may be possible for an attacker to execute arbitrary code through this vulnerability.
A restart of the server is required in order to gain normal functionality.
This vulnerability has been reported to exist on systems running Windows NT 4.0 with either SP3, SP4, or SP6 installed.
The problem exists due to the interaction between WFTPD.EXE and the Windows function call 'NTDLL.DLL:RtlFreeHeap()'.
Invalid long strings submitted using either 'RETR' or 'CWD' commands to a host running WFTPD server, will result in the service terminating due to a buffer overflow. It may be possible for an attacker to execute arbitrary code through this vulnerability.
A restart of the server is required in order to gain normal functionality.
This vulnerability has been reported to exist on systems running Windows NT 4.0 with either SP3, SP4, or SP6 installed.
The problem exists due to the interaction between WFTPD.EXE and the Windows function call 'NTDLL.DLL:RtlFreeHeap()'.
Exploit / POC
WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
Len Budney <[email protected]> has provided the following exploit:
Len Budney <[email protected]> has provided the following exploit:
Solution / Fix
WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
Solution:
Texas Imperial Software has addressed this issue in WFTPD 3.00 R5 and 3.00 R5 Pro.
Texas Imperial Software WFTPD 3.0 0R4 Pro
Texas Imperial Software WFTPD 3.0 0R4
Solution:
Texas Imperial Software has addressed this issue in WFTPD 3.00 R5 and 3.00 R5 Pro.
Texas Imperial Software WFTPD 3.0 0R4 Pro
-
Texas Imperial Software protr300
http://www.wftpd.com/downloads/protr300.zip
Texas Imperial Software WFTPD 3.0 0R4
-
Texas Imperial Software 32wfd300
http://www.wftpd.com/downloads/32wfd300.zip
References
WFTPD 'RETR' and 'CWD' Buffer Overflow Vulnerability
References:
References:
- WFTPD Homepage (Texas Imperial Software)
- WFTPD Remote Buffer Overflow Vulnerability (SecurityFocus)