ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability
BID:6478
Info
ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 6478 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 24 2002 12:00AM |
| Updated: | Dec 24 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to spinez. |
| Vulnerable: |
NcFTP Software NcFTPD 2.7.1 |
| Not Vulnerable: | |
Discussion
ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability
A vulnerability has been reported for ncftpd. The problem occurs in the STAT function when used in conjuction with file globbing. This issue can be triggered by a malicious STAT request for a directory with a filename of excessive length. The problem is due to filename expansion which is due to special characters used during the request.
It should be noted that this vulnerability has been reported to exist in version 2.7.1.
The vendor has announced that nctpd is in fact not vulnerable to this issue.
Symantec has been unable to reproduce this vulnerability.
A vulnerability has been reported for ncftpd. The problem occurs in the STAT function when used in conjuction with file globbing. This issue can be triggered by a malicious STAT request for a directory with a filename of excessive length. The problem is due to filename expansion which is due to special characters used during the request.
It should be noted that this vulnerability has been reported to exist in version 2.7.1.
The vendor has announced that nctpd is in fact not vulnerable to this issue.
Symantec has been unable to reproduce this vulnerability.
Exploit / POC
ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability
It has been confirmed that an exploit for this vulnerability is available. It should be noted however that reports indicate this exploit may be a fake and is in fact a trojan.
It has been confirmed that an exploit for this vulnerability is available. It should be noted however that reports indicate this exploit may be a fake and is in fact a trojan.