Frox FTP Cache Retrieval Buffer Overflow Vulnerability
BID:3606
Info
Frox FTP Cache Retrieval Buffer Overflow Vulnerability
| Bugtraq ID: | 3606 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2001 12:00AM |
| Updated: | Nov 30 2001 12:00AM |
| Credit: | This vulnerability was announced by James Hollingshead <[email protected]> via Bugtraq on November 30, 2001. |
| Vulnerable: |
frox frox 0.6.6 frox frox 0.6.5 frox frox 0.6.4 frox frox 0.6.3 frox frox 0.6.2 frox frox 0.6.1 frox frox 0.6 .0 |
| Not Vulnerable: |
frox frox 0.6.7 |
Discussion
Frox FTP Cache Retrieval Buffer Overflow Vulnerability
Frox is a freely available, open source FTP proxy software package. It is maintained by public domain, and indexed by Sourceforge.
frox is vulnerable to a buffer overflow. If the caching option is enabled, a file downloaded from a long path can overflow a routine that writes the header file information.
This makes it possible for a malicious ftp server to spawn a shell allowing local access on a system running the vulnerable software. The frox program is typically not a root-run process.
Frox is a freely available, open source FTP proxy software package. It is maintained by public domain, and indexed by Sourceforge.
frox is vulnerable to a buffer overflow. If the caching option is enabled, a file downloaded from a long path can overflow a routine that writes the header file information.
This makes it possible for a malicious ftp server to spawn a shell allowing local access on a system running the vulnerable software. The frox program is typically not a root-run process.
Exploit / POC
Frox FTP Cache Retrieval Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Frox FTP Cache Retrieval Buffer Overflow Vulnerability
Solution:
Fixed version available:
frox frox 0.6 .0
frox frox 0.6.1
frox frox 0.6.2
frox frox 0.6.3
frox frox 0.6.4
frox frox 0.6.5
frox frox 0.6.6
Solution:
Fixed version available:
frox frox 0.6 .0
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.1
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.2
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.3
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.4
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.5
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz
frox frox 0.6.6
-
frox frox-0.6.7.tar.gz
http://www.hollo.org/frox/download/frox-0.6.7.tar.gz