Ipswitch WS_FTP Server 'STAT' Buffer Overflow Vulnerability
BID:3507
Info
Ipswitch WS_FTP Server 'STAT' Buffer Overflow Vulnerability
| Bugtraq ID: | 3507 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2001 12:00AM |
| Updated: | Nov 05 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by andreas junestam <[email protected]> on Nov 5, 2001. |
| Vulnerable: |
Ipswitch WS FTP Server 2.0.3 Ipswitch WS FTP Server 2.0.2 Ipswitch WS FTP Server 2.0.1 Ipswitch WS FTP Server 2.0 Ipswitch WS FTP Server 1.0.5 Ipswitch WS FTP Server 1.0.4 Ipswitch WS FTP Server 1.0.3 Ipswitch WS FTP Server 1.0.2 Ipswitch WS FTP Server 1.0.1 |
| Not Vulnerable: |
Ipswitch WS FTP Server 2.0.4 |
Discussion
Ipswitch WS_FTP Server 'STAT' Buffer Overflow Vulnerability
WS_FTP Server, a popular FTP server for Microsoft Windows platforms, is vulnerable to a buffer overflow condition when a user submits a specially crafted legitimate FTP command. WS_FTP Server by default runs as a SYSTEM service.
If a logged in user submits a 'STAT' command along with arbitrary characters (approx 479 bytes) to a host running WS_FTP Server, this could result in the overwriting of stack variables, including the return address, and potentially the execution of arbitrary code with SYSTEM privileges.
WS_FTP Server, a popular FTP server for Microsoft Windows platforms, is vulnerable to a buffer overflow condition when a user submits a specially crafted legitimate FTP command. WS_FTP Server by default runs as a SYSTEM service.
If a logged in user submits a 'STAT' command along with arbitrary characters (approx 479 bytes) to a host running WS_FTP Server, this could result in the overwriting of stack variables, including the return address, and potentially the execution of arbitrary code with SYSTEM privileges.
References
Ipswitch WS_FTP Server 'STAT' Buffer Overflow Vulnerability
References:
References:
- WS FTP Server Support Homepage (IPSwitch)
- WS_FTP Server 2.0.4 Upgrade Information (Ipswitch)