Bftpd Security Bypass Vulnerability
BID:40540
Info
Bftpd Security Bypass Vulnerability
| Bugtraq ID: | 40540 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2010 12:00AM |
| Updated: | Jun 02 2010 12:00AM |
| Credit: | Paul Laufer |
| Vulnerable: |
BFTPD Bftpd 2.2.1 BFTPD Bftpd 2.8 BFTPD Bftpd 2.4 |
| Not Vulnerable: |
BFTPD Bftpd 2.9 |
Discussion
Bftpd Security Bypass Vulnerability
Bftpd is prone to a security-bypass vulnerability that arises due to an access-validation error.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
The issue affects versions prior to Bftpd 2.9.
Bftpd is prone to a security-bypass vulnerability that arises due to an access-validation error.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the FTP server root directory. This may aid in further attacks.
The issue affects versions prior to Bftpd 2.9.
Exploit / POC
Bftpd Security Bypass Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
Bftpd Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.