TFTPD32 Arbitrary File Download/Upload Vulnerability
BID:6198
Info
TFTPD32 Arbitrary File Download/Upload Vulnerability
| Bugtraq ID: | 6198 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2002 12:00AM |
| Updated: | Nov 18 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Aviram Jenik" <[email protected]>. |
| Vulnerable: |
Philippe Jounin TFTPD32 2.50.2 Philippe Jounin TFTPD32 2.50 |
| Not Vulnerable: |
Philippe Jounin TFTPD32 2.51 |
Discussion
TFTPD32 Arbitrary File Download/Upload Vulnerability
A vulnerability has been discovered in Tftpd32 which allows a remote attacker to download and upload arbitrary system files. The ability to upload system files may allow an attacker to replaced key system files with trojaned copies, used to open backdoors into a target system.
A vulnerability has been discovered in Tftpd32 which allows a remote attacker to download and upload arbitrary system files. The ability to upload system files may allow an attacker to replaced key system files with trojaned copies, used to open backdoors into a target system.
Exploit / POC
TFTPD32 Arbitrary File Download/Upload Vulnerability
The following proof of concepts were provided:
tftp host GET /boot.ini
tftp host PUT myfile /boot.ini
The following proof of concepts were provided:
tftp host GET /boot.ini
tftp host PUT myfile /boot.ini
Solution / Fix
TFTPD32 Arbitrary File Download/Upload Vulnerability
Solution:
Fixes are available:
Philippe Jounin TFTPD32 2.50
Philippe Jounin TFTPD32 2.50.2
Solution:
Fixes are available:
Philippe Jounin TFTPD32 2.50
-
Tftpd32 tftpd32j.zip
http://perso.wanadoo.fr/philippe.jounin/download/tftpd32j.zip
Philippe Jounin TFTPD32 2.50.2
-
Tftpd32 tftpd32j.zip
http://perso.wanadoo.fr/philippe.jounin/download/tftpd32j.zip
References
TFTPD32 Arbitrary File Download/Upload Vulnerability
References:
References:
- Home Page (Tftpd32)
- TFTPD32 Directory Traversal Vulnerability ("Aviram Jenik"
)