Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
BID:6345
Info
Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
| Bugtraq ID: | 6345 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2002 12:00AM |
| Updated: | Dec 09 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Tamer Sahin <[email protected]>. |
| Vulnerable: |
Mollensoft Software Enceladus Server Suite 3.9 |
| Not Vulnerable: | |
Discussion
Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
Enceladus Server Suite is prone to a remotely exploitable buffer overflow vulnerability. It is possible to trigger this condition by supplying an overly long value for several FTP commands. To exploit this issue, the attacker must be able to authenticate to the FTP server included in Enceladus and issue a maliciously crafted command.
Successful exploitation will enable a remote attacker to execute arbitrary code with the privileges of the Enceladus Server Suite software, which will most likely run with SYSTEM (or equivalent) privileges. This vulnerability may also be used to cause a denial of service.
This issue has been reported for Enceladus Server Suite 3.9. Other versions may also be affected.
Enceladus Server Suite is prone to a remotely exploitable buffer overflow vulnerability. It is possible to trigger this condition by supplying an overly long value for several FTP commands. To exploit this issue, the attacker must be able to authenticate to the FTP server included in Enceladus and issue a maliciously crafted command.
Successful exploitation will enable a remote attacker to execute arbitrary code with the privileges of the Enceladus Server Suite software, which will most likely run with SYSTEM (or equivalent) privileges. This vulnerability may also be used to cause a denial of service.
This issue has been reported for Enceladus Server Suite 3.9. Other versions may also be affected.
Exploit / POC
Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
A proof of concept has been made available by Sapient2003.
A proof of concept has been made available by Sapient2003.
Solution / Fix
Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mollensoft Software Enceladus Server Suite FTP Command Buffer Overflow Vulnerability
References:
References:
- Home Page (Mollensoft Software)
- [SecurityOffice] Enceladus Server Suite v3.9 Buffer Overflow Vulnerability (Tamer Sahin
) - Multiple vulnerability in Enceladus Server (securma massine
)