3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
BID:6297
Info
3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
| Bugtraq ID: | 6297 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2002 12:00AM |
| Updated: | Dec 02 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Michael S. Scheidell" <[email protected]>. |
| Vulnerable: |
Nortel Networks CS 1000 3Com 3Com SuperStack 3 NBX 4.1.21 3Com 3Com SuperStack 3 NBX 4.1.4 3Com 3Com SuperStack 3 NBX 4.0.17 |
| Not Vulnerable: | |
Discussion
3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
It has been reported that the ftpd server, included in the Embedded Real Time Operating System (ERTOS) of 3Com Superstack 3 NBX IP phones, contains a denial of service vulnerability. This issue can be triggered by sending a CEL paramater of excessive length, effectively causing the ftpd server and various VoIP services to no longer respond.
It should be noted that this issue may be similar to the vulnerability described in BID 679.
Although unconfirmed, it should also be noted that due to the nature of this vulnerability under some circumstances it may be exploited to execute arbitrary code.
It has been reported that the ftpd server, included in the Embedded Real Time Operating System (ERTOS) of 3Com Superstack 3 NBX IP phones, contains a denial of service vulnerability. This issue can be triggered by sending a CEL paramater of excessive length, effectively causing the ftpd server and various VoIP services to no longer respond.
It should be noted that this issue may be similar to the vulnerability described in BID 679.
Although unconfirmed, it should also be noted that due to the nature of this vulnerability under some circumstances it may be exploited to execute arbitrary code.
Exploit / POC
3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
The following proof of concept has been supplied.
CEL aaaa[...]aaaa where string is 2048 bytes long
The following proof of concept has been supplied.
CEL aaaa[...]aaaa where string is 2048 bytes long
Solution / Fix
3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
Solution:
Nortel Networks has released an advisory and an update to address this issue. Customers are advised to peruse the referenced advisory (PDF) for further information.
This issue has reportedly been confirmed by the vendor, although no patch is currently available to resolve this issue.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Nortel Networks has released an advisory and an update to address this issue. Customers are advised to peruse the referenced advisory (PDF) for further information.
This issue has reportedly been confirmed by the vendor, although no patch is currently available to resolve this issue.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
3Com SuperStack 3 NBX FTPD Denial of Service Vulnerability
References:
References:
- Denial Of Service Attack /FTP Server Crash Fixed For CS 1000 (Nortel Networks)
- [VU#317417] Denial of Service condition in vxworks ftpd/3com nbx ("Michael S. Scheidell"
) - 3com NBX IP Phone Call manager Denial of Service - Update (Michael Scheidell
)