AFTPD Home Directory Change Core Dump Vulnerability
BID:3806
Info
AFTPD Home Directory Change Core Dump Vulnerability
| Bugtraq ID: | 3806 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0104 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Nu Omega Tau <[email protected]> via Bugtraq on January 7, 2002. |
| Vulnerable: |
AFTPD AFTPD 5.4.4 |
| Not Vulnerable: | |
Discussion
AFTPD Home Directory Change Core Dump Vulnerability
AFTPD is an alternate FTP daemon used on some UNIX Operating systems.
A problem with AFTPD has been discovered that could allow a remote user to gain elevated privileges. The problem is in the handling of input.
The problem presents itself when a user accesses the ftp server via any type of user account (regular, or anonymous). A user attempting to change to the user's specified home directory via a tilde (~) may crash the ftp server, creating a core file in the CWD. Upon connecting to the server and deliberately failing to authenticate as a user, this could force loading of the entire password file into system memory. The core file would then contain the encrypted passwords.
This makes it possible for a remote user with anonymous access to gain access to sensitive information, and could lead to elevated privileges.
AFTPD is an alternate FTP daemon used on some UNIX Operating systems.
A problem with AFTPD has been discovered that could allow a remote user to gain elevated privileges. The problem is in the handling of input.
The problem presents itself when a user accesses the ftp server via any type of user account (regular, or anonymous). A user attempting to change to the user's specified home directory via a tilde (~) may crash the ftp server, creating a core file in the CWD. Upon connecting to the server and deliberately failing to authenticate as a user, this could force loading of the entire password file into system memory. The core file would then contain the encrypted passwords.
This makes it possible for a remote user with anonymous access to gain access to sensitive information, and could lead to elevated privileges.
Exploit / POC
AFTPD Home Directory Change Core Dump Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
AFTPD Home Directory Change Core Dump Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AFTPD Home Directory Change Core Dump Vulnerability
References:
References: