Sharp Zaurus Remote FTP Server Root Access Vulnerability
BID:5200
Info
Sharp Zaurus Remote FTP Server Root Access Vulnerability
| Bugtraq ID: | 5200 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2002 12:00AM |
| Updated: | Jul 10 2002 12:00AM |
| Credit: | Vulnerability discovery credited to SURUAZ <[email protected]>. |
| Vulnerable: |
Sharp Zaurus SL-5500 Sharp Zaurus SL-5000D |
| Not Vulnerable: | |
Discussion
Sharp Zaurus Remote FTP Server Root Access Vulnerability
Zaurus is a handheld device distributed by Sharp Electronics.
The FTP daemon used with the Sharp Zaurus to sync the handheld does not require authentication. A remote user with access to the device via the network may log into the device as root without the need for a password. This problem is further compounded by the fact that the FTP daemon binds to all interfaces on the device.
Zaurus is a handheld device distributed by Sharp Electronics.
The FTP daemon used with the Sharp Zaurus to sync the handheld does not require authentication. A remote user with access to the device via the network may log into the device as root without the need for a password. This problem is further compounded by the fact that the FTP daemon binds to all interfaces on the device.
Exploit / POC
Sharp Zaurus Remote FTP Server Root Access Vulnerability
This vulnerability may be exploited with an FTP client.
This vulnerability may be exploited with an FTP client.
Solution / Fix
Sharp Zaurus Remote FTP Server Root Access Vulnerability
Solution:
It has been reported that this issue is fixed on the latest ROM of the software. This is, however, not confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue is fixed on the latest ROM of the software. This is, however, not confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sharp Zaurus Remote FTP Server Root Access Vulnerability
References:
References: