Cat Soft Serv-U Buffer Overflow Vulnerabilities
BID:269
Info
Cat Soft Serv-U Buffer Overflow Vulnerabilities
| Bugtraq ID: | 269 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 1999 12:00AM |
| Updated: | May 03 1999 12:00AM |
| Credit: | This vulnerability was published by Arne Vidstrom <[email protected]>. Exploit by UNYUN <[email protected]>. |
| Vulnerable: |
Cat Soft Serv-U 2.5 |
| Not Vulnerable: |
Cat Soft Serv-U 2.5 a |
Discussion
Cat Soft Serv-U Buffer Overflow Vulnerabilities
The Serv-U FTP server versions 2.5 and earlier are vulnerable to multiple buffer overflows. This can result in a denial of service and at worst in arbitrary code being executed on the system.
The vulnerabilities are in the CWD and LS FTP commands if they are passed an argument a string longer than 155 characters.
The Serv-U FTP server versions 2.5 and earlier are vulnerable to multiple buffer overflows. This can result in a denial of service and at worst in arbitrary code being executed on the system.
The vulnerabilities are in the CWD and LS FTP commands if they are passed an argument a string longer than 155 characters.
Exploit / POC
Cat Soft Serv-U Buffer Overflow Vulnerabilities
The following exploit is know to work under Serv-U 2.5 under Windows 98. Changing the parameter may make it work under other environments.
The following exploit is know to work under Serv-U 2.5 under Windows 98. Changing the parameter may make it work under other environments.
Solution / Fix
Cat Soft Serv-U Buffer Overflow Vulnerabilities
Solution:
Cat Soft has made an upgrade available which solves this and other issues. It can be obtained at:
http://www.ftpserv-u.com/download.cfm
Solution:
Cat Soft has made an upgrade available which solves this and other issues. It can be obtained at:
http://www.ftpserv-u.com/download.cfm