ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
BID:8679
Info
ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
| Bugtraq ID: | 8679 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0831 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery is credited to Mark Dowd of ISS X-Force. |
| Vulnerable: |
Sun Cobalt RaQ XTR ProFTPD Project ProFTPD 1.2.9 rc2 ProFTPD Project ProFTPD 1.2.9 rc1 ProFTPD Project ProFTPD 1.2.8 rc2 ProFTPD Project ProFTPD 1.2.8 rc1 ProFTPD Project ProFTPD 1.2.8 ProFTPD Project ProFTPD 1.2.7 rc3 ProFTPD Project ProFTPD 1.2.7 rc2 ProFTPD Project ProFTPD 1.2.7 rc1 ProFTPD Project ProFTPD 1.2.7 |
| Not Vulnerable: |
ProFTPD Project ProFTPD 1.2.9 rc3 ProFTPD Project ProFTPD 1.2.9 |
Discussion
ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
A remotely exploitable buffer overrun vulnerability has been reported in ProFTPD. This issue could be triggered if an attacker uploads a malformed file and then that file is downloaded in ASCII mode. Successful exploitation will permit a malicious FTP user with upload access to execute arbitrary code in the context of the FTP server.
It is also reported that ProFTPD does not adequately drop privileges in some circumstances, which may compound the risks associated with exploitation.
This issue could also affect versions prior to 1.2.7, though this has not been confirmed.
A remotely exploitable buffer overrun vulnerability has been reported in ProFTPD. This issue could be triggered if an attacker uploads a malformed file and then that file is downloaded in ASCII mode. Successful exploitation will permit a malicious FTP user with upload access to execute arbitrary code in the context of the FTP server.
It is also reported that ProFTPD does not adequately drop privileges in some circumstances, which may compound the risks associated with exploitation.
This issue could also affect versions prior to 1.2.7, though this has not been confirmed.
Exploit / POC
ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
Exploit code is available:
Exploit code is available:
Solution / Fix
ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
Solution:
The vendor has stated that patched versions of ProFTPD 1.2.7 through 1.2.9rc2 have been made available. These patched versions can be obtained from the vendor through various mirrors and are denoted with a 'p' after the version number, for example:
proftpd-1.2.7p.tar.gz
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
Slackware has released fixes to address this issue.
OpenPKG updates are available. See advisory OpenPKG-SA-2003.043.
Mandrake has issued fixes listed in advisory MDKSA-2003:095. **UPDATE: On Dec 31, 2003 Mandrake released new fixes correcting a bug in the patched version of ProFTPD.
Trustix has issued fixes for Trustix Secure Linux. See advisory TSLSA-2003-0037 in the reference section.
GENTOO has released an advisory 200309-16 and fix information to address this issue. Please see the referenced advisory for more information.
Conectiva has released advisory CLA-2003:750 to address this issue.
Turbolinux has released an advisory TLSA-2003-54 and fix information to address this issue. Please see the referenced advisory for more information.
ProFTPD versions 1.2.9 and 1.2.9rc3 have been released which are not prone to this issue. Users are advised to obtain the fixes.
Sun has released a fix for the Qube3.
Sun Cobalt RaQ XTR
ProFTPD Project ProFTPD 1.2.7
ProFTPD Project ProFTPD 1.2.7 rc2
ProFTPD Project ProFTPD 1.2.7 rc3
ProFTPD Project ProFTPD 1.2.7 rc1
ProFTPD Project ProFTPD 1.2.8
ProFTPD Project ProFTPD 1.2.8 rc1
ProFTPD Project ProFTPD 1.2.8 rc2
ProFTPD Project ProFTPD 1.2.9 rc1
ProFTPD Project ProFTPD 1.2.9 rc2
Solution:
The vendor has stated that patched versions of ProFTPD 1.2.7 through 1.2.9rc2 have been made available. These patched versions can be obtained from the vendor through various mirrors and are denoted with a 'p' after the version number, for example:
proftpd-1.2.7p.tar.gz
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
Slackware has released fixes to address this issue.
OpenPKG updates are available. See advisory OpenPKG-SA-2003.043.
Mandrake has issued fixes listed in advisory MDKSA-2003:095. **UPDATE: On Dec 31, 2003 Mandrake released new fixes correcting a bug in the patched version of ProFTPD.
Trustix has issued fixes for Trustix Secure Linux. See advisory TSLSA-2003-0037 in the reference section.
GENTOO has released an advisory 200309-16 and fix information to address this issue. Please see the referenced advisory for more information.
Conectiva has released advisory CLA-2003:750 to address this issue.
Turbolinux has released an advisory TLSA-2003-54 and fix information to address this issue. Please see the referenced advisory for more information.
ProFTPD versions 1.2.9 and 1.2.9rc3 have been released which are not prone to this issue. Users are advised to obtain the fixes.
Sun has released a fix for the Qube3.
Sun Cobalt RaQ XTR
-
Sun RaQXTR-All-Security-1.0.2-16623.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.2-16623.pkg
ProFTPD Project ProFTPD 1.2.7
-
Conectiva proftpd-1.2.7-27285U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/proftpd-1.2.7-27285U90_2cl. i386.rpm -
Conectiva proftpd-doc-1.2.7-27285U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/proftpd-doc-1.2.7-27285U90_ 2cl.i386.rpm -
Mandrake proftpd-1.2.8-1.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake proftpd-1.2.8-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake proftpd-anonymous-1.2.8-1.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake proftpd-anonymous-1.2.8-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
ProFTPD Project ProFTPD 1.2.9
http://proftpd.linux.co.uk/download.html -
Sun Qube3-All-Security-4.0.2-16623.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0 .2-16623.pkg
ProFTPD Project ProFTPD 1.2.7 rc2
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.7 rc3
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.7 rc1
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.8
-
Mandrake proftpd-1.2.8-5.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake proftpd-anonymous-1.2.8-5.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
ProFTPD Project ProFTPD 1.2.9
http://proftpd.linux.co.uk/download.html -
Slackware proftpd-1.2.8p-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/p roftpd-1.2.8p-i386-1.tgz -
Slackware proftpd-1.2.8p-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/p roftpd-1.2.8p-i386-1.tgz -
Slackware proftpd-1.2.8p-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/pr oftpd-1.2.8p-i486-1.tgz
ProFTPD Project ProFTPD 1.2.8 rc1
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.8 rc2
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.9 rc1
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
ProFTPD Project ProFTPD 1.2.9 rc2
-
ProFTPD Project ProFTPD 1.2.9rc3
http://proftpd.linux.co.uk/download.html
References
ProFTPD ASCII File Transfer Buffer Overrun Vulnerability
References:
References:
- [slackware-security] ProFTPD Security Advisory (SSA:2003-259-02) (Slackware)
- ProFTPD ASCII File Remote Compromise Vulnerability (ISS)
- ProFTPD Home Page (ProFTPD)
- ProFTPD Remote Exploit (ProFTPD)
- RaQ XTR Patch Page (Sun)
- Remote root exploit for proftpd \n bug (Carl Livitt
)