Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
BID:32558
Info
Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 32558 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2008 12:00AM |
| Updated: | Dec 01 2008 11:53PM |
| Credit: | Blue Moon Consulting |
| Vulnerable: |
Maxum Rumpus FTP Server 6.0 |
| Not Vulnerable: |
Maxum Rumpus FTP Server 6.0.1 |
Discussion
Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
Maxum Rumpus is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, possibly with root privileges. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Rumpus 6.0.1 are vulnerable.
Maxum Rumpus is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, possibly with root privileges. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Rumpus 6.0.1 are vulnerable.
Exploit / POC
Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an updated version; please see the references for more information.
Solution:
The vendor has released an updated version; please see the references for more information.
References
Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability
References:
References:
- Rumpus 6.0.1 Is Now Available (Maxum)
- Rumpus FTP Server Product Page (Maxum)
- [BMSA 2008-09] Two buffer overflow vulnerabilities in Rumpus v6.0 (Nam Nguyen
)