Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
BID:8668
Info
Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
| Bugtraq ID: | 8668 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2003 12:00AM |
| Updated: | Sep 22 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Adam Zabrocki <[email protected]>. |
| Vulnerable: |
Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.1 Washington University wu-ftpd 2.6 .0 Washington University wu-ftpd 2.5 .0 |
| Not Vulnerable: | |
Discussion
Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
A remote stack-based buffer overrun has been reported for Wu-Ftpd. The problem occurs due to insufficient bounds checking when handling input within the SockPrintf() function. As a result, a remote attacker capable of creating a file path of excessive length, could potentially trigger the overrun.
Successful exploitation of this vulnerability would ultimately allow for the execution of arbitrary code with the privileges of the Wu-Ftpd server, typically root.
It should be noted that this vulnerability is not present within the default installation of Wu-Ftpd. The server must be configured using the 'MAIL_ADMIN' option to notify an administrator when a file has been uploaded.
A remote stack-based buffer overrun has been reported for Wu-Ftpd. The problem occurs due to insufficient bounds checking when handling input within the SockPrintf() function. As a result, a remote attacker capable of creating a file path of excessive length, could potentially trigger the overrun.
Successful exploitation of this vulnerability would ultimately allow for the execution of arbitrary code with the privileges of the Wu-Ftpd server, typically root.
It should be noted that this vulnerability is not present within the default installation of Wu-Ftpd. The server must be configured using the 'MAIL_ADMIN' option to notify an administrator when a file has been uploaded.
Exploit / POC
Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
Solution:
Slackware has released a security advisory and fixes to address this issue. See referenced advisory for additional details.
Solution:
Slackware has released a security advisory and fixes to address this issue. See referenced advisory for additional details.
References
Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
References:
References:
- Wu-Ftpd Homepage (Washington University)
- WU-FTPD Security Advisory (SSA:2003-259-03) (Slackware)
- Wu_ftpd all versions (not) vulnerability. (Adam Zabrocki
)