Wu-ftpd SITE NEWER Denial of Service Vulnerability
BID:737
Info
Wu-ftpd SITE NEWER Denial of Service Vulnerability
| Bugtraq ID: | 737 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 1999 12:00AM |
| Updated: | Oct 21 1999 12:00AM |
| Credit: | Released in CERT advisory CA-99-13, posted to BugTraq on Oct 19, 1999 and originally AUSCERT advisory AA-99.02, published on Oct 19, 1999. |
| Vulnerable: |
Washington University wu-ftpd 2.5 .0 |
| Not Vulnerable: |
Washington University wu-ftpd 2.6 .0 |
Discussion
Wu-ftpd SITE NEWER Denial of Service Vulnerability
It may be possible for remote users to cause wu-ftpd to consume large amounts of memory, creating a denial of service. If users can upload files, arbitrary code can be executed with the uid of the ftpd (usually root).
It may be possible for remote users to cause wu-ftpd to consume large amounts of memory, creating a denial of service. If users can upload files, arbitrary code can be executed with the uid of the ftpd (usually root).
Exploit / POC
Wu-ftpd SITE NEWER Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Wu-ftpd SITE NEWER Denial of Service Vulnerability
Solution:
You can upgrade to the newest version of Wu-ftpd (2.6) for any vulnerable platform.
RedHat has released patches available at the following locations:
Red Hat Linux 4.2
- -----------------
Intel:
ftp://updates.redhat.com//4.2/i386/wu-ftpd-2.6.0-0.4.2.i386.rpm
Alpha:
ftp://updates.redhat.com//4.2/alpha/wu-ftpd-2.6.0-0.4.2.alpha.rpm
Sparc:
ftp://updates.redhat.com//4.2/sparc/wu-ftpd-2.6.0-0.4.2.sparc.rpm
Source packages:
ftp://updates.redhat.com//4.2/SRPMS/wu-ftpd-2.6.0-0.4.2.src.rpm
Red Hat Linux 5.2
- -----------------
Intel:
ftp://updates.redhat.com//5.2/i386/wu-ftpd-2.6.0-0.5.x.i386.rpm
Alpha:
ftp://updates.redhat.com//5.2/alpha/wu-ftpd-2.6.0-0.5.x.alpha.rpm
Sparc:
ftp://updates.redhat.com//5.2/sparc/wu-ftpd-2.6.0-0.5.x.sparc.rpm
Source packages:
ftp://updates.redhat.com//5.2/SRPMS/wu-ftpd-2.6.0-0.5.x.src.rpm
Red Hat Linux 6.x
- -----------------
Intel:
ftp://updates.redhat.com//6.0/i386/wu-ftpd-2.6.0-1.i386.rpm
Alpha:
ftp://updates.redhat.com//6.0/alpha/wu-ftpd-2.6.0-1.alpha.rpm
Sparc:
ftp://updates.redhat.com//6.0/sparc/wu-ftpd-2.6.0-1.sparc.rpm
Source packages:
ftp://updates.redhat.com//6.0/SRPMS/wu-ftpd-2.6.0-1.src.rpm
Solution:
You can upgrade to the newest version of Wu-ftpd (2.6) for any vulnerable platform.
RedHat has released patches available at the following locations:
Red Hat Linux 4.2
- -----------------
Intel:
ftp://updates.redhat.com//4.2/i386/wu-ftpd-2.6.0-0.4.2.i386.rpm
Alpha:
ftp://updates.redhat.com//4.2/alpha/wu-ftpd-2.6.0-0.4.2.alpha.rpm
Sparc:
ftp://updates.redhat.com//4.2/sparc/wu-ftpd-2.6.0-0.4.2.sparc.rpm
Source packages:
ftp://updates.redhat.com//4.2/SRPMS/wu-ftpd-2.6.0-0.4.2.src.rpm
Red Hat Linux 5.2
- -----------------
Intel:
ftp://updates.redhat.com//5.2/i386/wu-ftpd-2.6.0-0.5.x.i386.rpm
Alpha:
ftp://updates.redhat.com//5.2/alpha/wu-ftpd-2.6.0-0.5.x.alpha.rpm
Sparc:
ftp://updates.redhat.com//5.2/sparc/wu-ftpd-2.6.0-0.5.x.sparc.rpm
Source packages:
ftp://updates.redhat.com//5.2/SRPMS/wu-ftpd-2.6.0-0.5.x.src.rpm
Red Hat Linux 6.x
- -----------------
Intel:
ftp://updates.redhat.com//6.0/i386/wu-ftpd-2.6.0-1.i386.rpm
Alpha:
ftp://updates.redhat.com//6.0/alpha/wu-ftpd-2.6.0-1.alpha.rpm
Sparc:
ftp://updates.redhat.com//6.0/sparc/wu-ftpd-2.6.0-1.sparc.rpm
Source packages:
ftp://updates.redhat.com//6.0/SRPMS/wu-ftpd-2.6.0-1.src.rpm
References
Wu-ftpd SITE NEWER Denial of Service Vulnerability
References:
References:
- Updates, Fixes, and Errata Page (RedHat)