Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
BID:33112
Info
Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
| Bugtraq ID: | 33112 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2009 12:00AM |
| Updated: | Jan 05 2009 09:32PM |
| Credit: | Aditya K Sood |
| Vulnerable: |
Google Chrome 1.0.154.36 |
| Not Vulnerable: | |
Discussion
Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
Google Chrome is prone to an information-disclosure vulnerability because it fails to adequately validate server-issued instructions while in PASV (passive) mode.
Attackers can exploit this issue to port-scan networks inside a victim computer's firewall. Information harvested may aid in further attacks.
Google Chrome 1.0.154.36 is affected; other versions may also be vulnerable.
Google Chrome is prone to an information-disclosure vulnerability because it fails to adequately validate server-issued instructions while in PASV (passive) mode.
Attackers can exploit this issue to port-scan networks inside a victim computer's firewall. Information harvested may aid in further attacks.
Google Chrome 1.0.154.36 is affected; other versions may also be vulnerable.
Exploit / POC
Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into connecting to a malicious FTP server.
The following proof-of-concept code is available:
To exploit this issue an attacker must entice an unsuspecting victim into connecting to a malicious FTP server.
The following proof-of-concept code is available:
Solution / Fix
Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Google Chrome FTP Client PASV Port Scan Information Disclosure Vulnerability
References:
References:
- Google Chrome FTP PASV IP Malicious Port Scanning Vulnerability. (Secniche.org)
- Google Chrome Homepage (Google)
- Google Chrome FTP PASV IP Malicious Port Scanning Vulnerability. (Aditya K Sood <[email protected]>)