ProFTPD Remote Buffer Overflow
BID:612
Info
ProFTPD Remote Buffer Overflow
| Bugtraq ID: | 612 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0911 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | The first information about this vulnerability came in the form of an exploit posted by <[email protected]> to the BUGTRAQ mailing list. The information for the vulnerability in 1.2pre4 was posted to Bugtraq by Renaud Deraison. |
| Vulnerable: |
ProFTPD Project ProFTPD 1.2 pre5 ProFTPD Project ProFTPD 1.2 pre4 ProFTPD Project ProFTPD 1.2 pre3 ProFTPD Project ProFTPD 1.2 pre2 ProFTPD Project ProFTPD 1.2 pre1 |
| Not Vulnerable: |
ProFTPD Project ProFTPD 1.2 pre6 |
Discussion
ProFTPD Remote Buffer Overflow
The vulnerability in 1.2pre1, 1.2pre3 and 1.2pre3 is a remotely exploitable buffer overflow, the result of a sprintf() in the log_xfer() routine in src/log.c.
The vulnerability in 1.2pre4 is a mkdir overflow. The name of the created path can not exceed 255 chars.
1.2pre6 limits the command buffer size to 512 characters in src/main.c and modifies the fix from 1.2pre4.
The vulnerability in 1.2pre1, 1.2pre3 and 1.2pre3 is a remotely exploitable buffer overflow, the result of a sprintf() in the log_xfer() routine in src/log.c.
The vulnerability in 1.2pre4 is a mkdir overflow. The name of the created path can not exceed 255 chars.
1.2pre6 limits the command buffer size to 512 characters in src/main.c and modifies the fix from 1.2pre4.
Exploit / POC
ProFTPD Remote Buffer Overflow
exploit available
exploit available
Solution / Fix
ProFTPD Remote Buffer Overflow
Solution:
Upgrade to ProFTPD 1.2.0pre6, available at:
ftp.tos.net/pub/proftpd
or
ftp.proftpd.net/pub/proftpd
RedHat Linux 6.0:
Intel:
ftp://updates.redhat.com/powertools/6.0/i386/proftpd-1.2.0pre3-6.i386.rpm
Alpha:
ftp://updates.redhat.com/powertools/6.0/alpha/proftpd-1.2.0pre3-6.alpha.rpm
Sparc:
ftp://updates.redhat.com/powertools/6.0/sparc/proftpd-1.2.0pre3-6.sparc.rpm
Source packages:
ftp://updates.redhat.com/powertools/6.0/SRPMS/proftpd-1.2.0pre3-6.src.rpm
Solution:
Upgrade to ProFTPD 1.2.0pre6, available at:
ftp.tos.net/pub/proftpd
or
ftp.proftpd.net/pub/proftpd
RedHat Linux 6.0:
Intel:
ftp://updates.redhat.com/powertools/6.0/i386/proftpd-1.2.0pre3-6.i386.rpm
Alpha:
ftp://updates.redhat.com/powertools/6.0/alpha/proftpd-1.2.0pre3-6.alpha.rpm
Sparc:
ftp://updates.redhat.com/powertools/6.0/sparc/proftpd-1.2.0pre3-6.sparc.rpm
Source packages:
ftp://updates.redhat.com/powertools/6.0/SRPMS/proftpd-1.2.0pre3-6.src.rpm