BrowseFTP Client Buffer Overflow Vulnerability
BID:3781
Info
BrowseFTP Client Buffer Overflow Vulnerability
| Bugtraq ID: | 3781 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2002 12:00AM |
| Updated: | Jan 04 2002 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Kanatoko <[email protected]>. |
| Vulnerable: |
BrowseFTP BrowseFTP Client 1.62 |
| Not Vulnerable: | |
Discussion
BrowseFTP Client Buffer Overflow Vulnerability
BrowseFTP is an ftp client that runs on various Microsoft Windows operating systems.
An issue has been reported which could allow for a malicious ftp server to execute arbitrary code on a BrowseFTP client user.
This is acheivable when a BrowseFTP user connects to an ftp host, if the FTP server '220' response is of excessive length. The stack-based overflow condition can allow for malicious administrators to execute arbitrary code on (and gain control of) client hosts. It is also possible to crash the client.
BrowseFTP is an ftp client that runs on various Microsoft Windows operating systems.
An issue has been reported which could allow for a malicious ftp server to execute arbitrary code on a BrowseFTP client user.
This is acheivable when a BrowseFTP user connects to an ftp host, if the FTP server '220' response is of excessive length. The stack-based overflow condition can allow for malicious administrators to execute arbitrary code on (and gain control of) client hosts. It is also possible to crash the client.
Exploit / POC
BrowseFTP Client Buffer Overflow Vulnerability
Kanatoko <[email protected]> has provided the following exploit. It is suggested that the exploit is invoked as an FTP server through inetd.
Kanatoko <[email protected]> has provided the following exploit. It is suggested that the exploit is invoked as an FTP server through inetd.
Solution / Fix
BrowseFTP Client Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.