GTKFTPD LIST Command Remote Buffer Overflow Vulnerability
BID:8486
Info
GTKFTPD LIST Command Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 8486 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2003 12:00AM |
| Updated: | Aug 25 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Vade 79 <[email protected]>. |
| Vulnerable: |
GtkFtpd gtkftp 1.0.4 GtkFtpd gtkftp 1.0.3 GtkFtpd gtkftp 1.0.2 |
| Not Vulnerable: | |
Discussion
GTKFTPD LIST Command Remote Buffer Overflow Vulnerability
The GtkFtpd LIST command routine has been reported prone to a remotely exploitable buffer overflow vulnerability.
The issue presents itself in the sys_cmd.c source file, and is due to a lack of sufficient bounds checking that is performed on user-supplied data. Ultimately this issue may be leveraged by a remote attacker to influence GtkFtpd program execution flow and have arbitrary supplied instructions executed in the context of the vulnerable daemon, typically root.
The GtkFtpd LIST command routine has been reported prone to a remotely exploitable buffer overflow vulnerability.
The issue presents itself in the sys_cmd.c source file, and is due to a lack of sufficient bounds checking that is performed on user-supplied data. Ultimately this issue may be leveraged by a remote attacker to influence GtkFtpd program execution flow and have arbitrary supplied instructions executed in the context of the vulnerable daemon, typically root.
Exploit / POC
GTKFTPD LIST Command Remote Buffer Overflow Vulnerability
The following proof of concept has been supplied:
The following proof of concept has been supplied:
Solution / Fix
GTKFTPD LIST Command Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.