SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
BID:5461
Info
SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
| Bugtraq ID: | 5461 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2002 12:00AM |
| Updated: | Aug 14 2002 12:00AM |
| Credit: | Vulnerability first detailed in SGI Security Advisory 20020305-03-I. |
| Vulnerable: |
SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: |
SGI IRIX 6.5.17 |
Discussion
SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
The FTP server included with SGI IRIX is vulnerable to hijacking of data connections when PASV mode is in use.
When in PASV mode, the server listens on a port when a transfer of data is to occur. The client then connects and the data is transferred. SGI has reported that the ftpd selects predictable PASV mode port numbers. As a result, it is trivial for remote attackers to hijack data connections and retrieve data before the client can.
The FTP server included with SGI IRIX is vulnerable to hijacking of data connections when PASV mode is in use.
When in PASV mode, the server listens on a port when a transfer of data is to occur. The client then connects and the data is transferred. SGI has reported that the ftpd selects predictable PASV mode port numbers. As a result, it is trivial for remote attackers to hijack data connections and retrieve data before the client can.
Exploit / POC
SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
Solution:
SGI have released an advisory (20030304-01-P) with details that address this issue. A number of patches to fix this vulnerability have also been provided. SGI have recommended that users upgrade to IRIX 6.5.20 or install the appropriate version specific patch.
Solution:
SGI have released an advisory (20030304-01-P) with details that address this issue. A number of patches to fix this vulnerability have also been provided. SGI have recommended that users upgrade to IRIX 6.5.20 or install the appropriate version specific patch.
References
SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
References:
References:
- Vulnerability Note VU#2558 (CERT)