Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
BID:5328
Info
Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
| Bugtraq ID: | 5328 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2002 12:00AM |
| Updated: | Jul 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to FX <[email protected]>, FtR <[email protected]>, and kim0 <[email protected]>. |
| Vulnerable: |
Cisco MGX 8850 - PXM1 1.2.10 Cisco MGX 8850 - PXM1 1.2.10 Cisco MGX 8250 1.2.10 Cisco MGX 8250 1.2.10 Cisco MGX 8230 1.2.10 Cisco MGX 8230 1.2.10 Cisco IOS 11.3 Cisco IOS 11.2 Cisco IOS 11.1 |
| Not Vulnerable: |
Cisco MGX 8850 - PXM1 1.2.11 Cisco MGX 8850 Cisco MGX 8830 Cisco MGX 8250 1.2.11 Cisco MGX 8230 1.2.11 Cisco IOS 12.1 Cisco IOS 12.0 |
Discussion
Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
A problem has been discovered in Cisco IOS and MGX switches that could result in a denial of service, and potential code execution.
It has been discovered that the TFTP server file name handling of Cisco IOS is vulnerable to a buffer overflow. This overflow results due insufficient bounds checking on requested file names. A request for a file name of 700 or more bytes will result a crash of the router, and reboot of the device.
On Cisco MGX switches, the TFTP service will fail but the device will continue to function.
Cisco IOS versions 12.0 and later are not prone to this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.
Cisco has announced that some MGX switches are also affected by this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.
A problem has been discovered in Cisco IOS and MGX switches that could result in a denial of service, and potential code execution.
It has been discovered that the TFTP server file name handling of Cisco IOS is vulnerable to a buffer overflow. This overflow results due insufficient bounds checking on requested file names. A request for a file name of 700 or more bytes will result a crash of the router, and reboot of the device.
On Cisco MGX switches, the TFTP service will fail but the device will continue to function.
Cisco IOS versions 12.0 and later are not prone to this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.
Cisco has announced that some MGX switches are also affected by this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.
Exploit / POC
Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
The following proof of concept has been made available by kim0 <[email protected]>.
tftp> get AAAAAAAAA....(700 times)
An exploit has been provided by FX <[email protected]>:
The following proof of concept has been made available by kim0 <[email protected]>.
tftp> get AAAAAAAAA....(700 times)
An exploit has been provided by FX <[email protected]>:
Solution / Fix
Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
Solution:
Cisco has announced that software upgrades will not be made available. The vendor has suggested the following workarounds in lieu of fixes:
Cisco has released MGX software 1.2.11 which addresses this issue. The fixes can be obtained if you have a service contract from the Software Center on Cisco's Worldwide Web site at http://www.cisco.com. Otherwise, further information on how to obtain this software can be obtained by contacting the vendor.
Solution:
Cisco has announced that software upgrades will not be made available. The vendor has suggested the following workarounds in lieu of fixes:
Cisco has released MGX software 1.2.11 which addresses this issue. The fixes can be obtained if you have a service contract from the Software Center on Cisco's Worldwide Web site at http://www.cisco.com. Otherwise, further information on how to obtain this software can be obtained by contacting the vendor.
References
Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
References:
References:
- Cisco Security Advisory: TFTP Long Filename Vulnerability (Cisco)
- Phenoelit Advisory
(Phenoelit Group)