Multiple Vendor 8.3 Filename Vulnerability

BID:584

Info

Multiple Vendor 8.3 Filename Vulnerability

Bugtraq ID: 584
Class: Access Validation Error
CVE:
Remote: Yes
Local: Yes
Published: Aug 16 1999 12:00AM
Updated: Aug 16 1999 12:00AM
Credit: Posted to Bugtraq August 19, 1999 by x-empt [ lvhc / lou ] <[email protected]>
Vulnerable: vqSoft vqServer for Windows 1.9
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Netscape FastTrack Server 3.0.1
Netscape FastTrack Server 2.0.1
Netscape Enterprise Server 3.0
- Compaq Tru64 4.0 d
- HP HP-UX 11.0
- IBM AIX 4.2.1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- SGI IRIX 6.5
- Sun Solaris 7.0
- Sun Solaris 2.6_sparc
Imatix Xitami for Windows 2.4 d2
- Microsoft Windows 3.1
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Cat Soft Serv-U 2.5 a
- Microsoft Windows 3.1
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Cat Soft Serv-U 2.5
- Microsoft Windows 3.1
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Not Vulnerable:

Discussion

Multiple Vendor 8.3 Filename Vulnerability

32bit Windows operating systems support long filenames, but also offer a means of compatibility with the older 8.3 filenames required by previous versions of DOS and Windows. This leads to problems with programs that have their own internal file security mechanisms.

In the Netscape, vqServer and Xitami webservers, restrictions applied to directories with long filenames will be ignored if the 8.3 version of the filename is requested. For example, if directory listing is enabled for c:\webroot\ and disabled for c:\webroot\longsubdir\ , a GET request for h t t p://server/longsubdir/ will fail, as expected. However, a GET request for h t t p://server/longsu~1/ will succeed.

In Serv-U, the 'cwd' and 'site exec' commands are susceptible to a similar vulnerability. If the execute permission is enabled for c:\ftproot\ and disabled for c:\ftproot\longsubdir\, and an executable is placed in C:\ftproot\longsubdir\, the command 'site exec C:\ftproot\longsubdir\example.exe' will fail, but 'site exec C:\ftproot\longsu~1\example.exe will work and the executable will be running.

As this is a problem with the maintenance of two different filesystem conventions in Windows32, the Windows 3.1 and non-Windows versions of these packages are not affected.

Other Windows32-based HTTP and FTP servers may have the same or similar vulnerabilities. If you are aware of any not listed here, please email us at: [email protected]

Exploit / POC

Multiple Vendor 8.3 Filename Vulnerability

see discussion

Solution / Fix

Multiple Vendor 8.3 Filename Vulnerability

Solution:
Netscape Enterprise and FastTrack Servers: Netscape has released patches for their servers. Contact Netscape for more information.

All other products: Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

References

Multiple Vendor 8.3 Filename Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report