IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
BID:41762
Info
IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
| Bugtraq ID: | 41762 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2010 12:00AM |
| Updated: | Sep 01 2010 06:37PM |
| Credit: | Kingcope |
| Vulnerable: |
IBM AIX FTP Server 0 IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
AIX FTP Server is prone to an information-disclosure vulnerability.
Remote attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
AIX FTP Server is prone to an information-disclosure vulnerability.
Remote attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
Exploit / POC
IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
The following exploits are available.
The following exploits are available.
Solution / Fix
IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
Updates are available; please see the references for more information.
IBM AIX 5.2
-
IBM ftpd_ifix.tar
http://aix.software.ibm.com/aix/efixes/security/ftpd_ifix.tar
IBM AIX 5.3
-
IBM ftpd_ifix.tar
http://aix.software.ibm.com/aix/efixes/security/ftpd_ifix.tar
References
IBM AIX FTP Server 'NLST' Command Information Disclosure Vulnerability
References:
References:
- IBM AIX Home Page (IBM)
- ftpd_advisory (IBM)