HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
BID:9175
Info
HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
| Bugtraq ID: | 9175 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 07 2003 12:00AM |
| Updated: | Dec 07 2003 12:00AM |
| Credit: | Discovery is credited to Xavier Brouckaert. |
| Vulnerable: |
hsftp hsftp 1.11 hsftp hsftp 1.10 hsftp hsftp 1.9 hsftp hsftp 1.7 hsftp hsftp 1.6 hsftp hsftp 1.5 hsftp hsftp 1.4 |
| Not Vulnerable: |
hsftp hsftp 1.13 |
Discussion
HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
hsftp is prone to a locally exploitable buffer overrun vulnerability due to insufficient bounds checking of hostname arguments supplied as command line input. In situations where hsftp is installed setuid root and not configured to drop privileges, this could be exploited to execute arbitrary code with elevated privileges.
hsftp is prone to a locally exploitable buffer overrun vulnerability due to insufficient bounds checking of hostname arguments supplied as command line input. In situations where hsftp is installed setuid root and not configured to drop privileges, this could be exploited to execute arbitrary code with elevated privileges.
Exploit / POC
HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
Solution:
This issue has been addressed in hsftp 1.13.
hsftp hsftp 1.10
hsftp hsftp 1.11
hsftp hsftp 1.4
hsftp hsftp 1.5
hsftp hsftp 1.6
hsftp hsftp 1.7
hsftp hsftp 1.9
Solution:
This issue has been addressed in hsftp 1.13.
hsftp hsftp 1.10
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.11
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.4
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.5
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.6
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.7
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
hsftp hsftp 1.9
-
hsftp hsftp-1.13.tar.gz
http://freshmeat.net/redir/hsftp/4159/url_tgz/hsftp-1.13.tar.gz
References
HSFTP Hostname Command Line Argument Buffer Overrun Vulnerability
References:
References:
- hsftp Homepage (hsftp)