lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

BID:9210

Info

lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

Bugtraq ID: 9210
Class: Boundary Condition Error
CVE: CVE-2003-0963
Remote: Yes
Local: No
Published: Dec 12 2003 12:00AM
Updated: Jul 12 2009 12:56AM
Credit: Discovered by Ulf Harnhammar <[email protected]>.
Vulnerable: Slackware Linux 9.1
Slackware Linux 9.0
Slackware Linux 8.1
Slackware Linux -current
SGI ProPack 2.4
SGI ProPack 2.3
lftp lftp 2.6.9
lftp lftp 2.6.8
lftp lftp 2.6.5
lftp lftp 2.6.4
lftp lftp 2.6.2
lftp lftp 2.6.1
lftp lftp 2.6
lftp lftp 2.5.4
lftp lftp 2.5.2
lftp lftp 2.5.1
Alexander V. Lukyanov lftp 2.6.9
+ OpenPKG OpenPKG Current
Alexander V. Lukyanov lftp 2.6.8
Alexander V. Lukyanov lftp 2.6.7
Alexander V. Lukyanov lftp 2.6.6
+ Mandriva Linux Mandrake 9.2
+ OpenPKG OpenPKG 1.3
+ Turbolinux Turbolinux Advanced Server 6.0
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Server 6.5
+ Turbolinux Turbolinux Server 6.1
+ Turbolinux Turbolinux Workstation 8.0
+ Turbolinux Turbolinux Workstation 7.0
Alexander V. Lukyanov lftp 2.6.5
+ Redhat Fedora Core1
Alexander V. Lukyanov lftp 2.6.4
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ OpenPKG OpenPKG 1.2
Alexander V. Lukyanov lftp 2.6.3
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
+ Redhat Linux 9.0 i386
Alexander V. Lukyanov lftp 2.6 .0
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.0
Alexander V. Lukyanov lftp 2.5.2
+ Redhat Linux 8.0 i386
Alexander V. Lukyanov lftp 2.4.9
+ Redhat Advanced Workstation for the Itanium Processor 2.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
Alexander V. Lukyanov lftp 2.3
Not Vulnerable: lftp lftp 2.6.10
Alexander V. Lukyanov lftp 2.6.10

Discussion

lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

It has been reported that the lftp file transfer client is vulnerable to a remotely exploitable buffer overflow condition. The vulnerability is present when lftp is used to retrieve content from a remote HTTP server. According to the report, the client does not properly handle special directories that exist on the server. These failures can be exploited by operators of web servers to execute arbitrary instructions on the host running lftp. Any such code would run with the privileges of the user who invoked lftp.

** This BID, originally entitled "LFTP Undisclosed HTML Parsing Vulnerability" described an issue that was also covered in BID 9212 "lftp Buffer Overflow Vulnerabilities". This BID has been revised with information from one of the vulnerabilities originally described in BID 9212. BID 9212 has also been revised to describe the other issue.

Exploit / POC

lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

[email protected] has supplied the following proof of concept exploit:

Solution / Fix

lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

Solution:
The vulnerability is fixed in version 2.6.10:

http://lftp.yar.ru/get.html

A patch that applies to 2.6.9 is also available:

http://labben.abm.uu.se/~ulha9485/lftp-advisory-data.tar.gz

OpenPKG has released an advisory (OpenPKG-SA-2003.053) with fixes to address these issues. Please see the referenced advisory for further information. Fixes are linked below.

SuSE has released an advisory with fixes to address these issues. Please see the referenced advisory for more information.

RedHat has released fixes for the Fedora project. Users are advised to download the fixed packages.

Mandrake has released advisory MDKSA-2003:116 with fixes to address this issue.

Red Hat has released security advisory RHSA-2003:403-01 to address this issue. Additionally, Red Hat has released advisory RHSA-2003:404-08 to address this issue in affected Enterprise operating systems. Users are advised to run up2date to resolve this issue.

Gentoo has released advisory 200312-07 to address this issue. Affected users are advised to execute the following commands:

emerge sync
emerge -pv '>=net-ftp/lftp-2.6.10'
emerge '>=net-ftp/lftp-2.6.10'
emerge clean

Slackware have released an advisory (SSA:2003-346-01) and fixes to address this issue.

Debian has released advisory DSA 406-1 to address this issue.

Conectiva has released advisory CLA-2004:800 to address this issue.

SGI has released SGI Advanced Linux Environment security update #8 (20040101-01-U) to provide fixes for this issue. Please see the attached advisory for more details.

TurboLinux has released advisory TLSA-2004-2 to address this issue. Please see the reference section for more details.

SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below:


Slackware Linux -current

SGI ProPack 2.3

SGI ProPack 2.4

Alexander V. Lukyanov lftp 2.4.9

Alexander V. Lukyanov lftp 2.5.2

Alexander V. Lukyanov lftp 2.6 .0

Alexander V. Lukyanov lftp 2.6.3

Alexander V. Lukyanov lftp 2.6.4

Alexander V. Lukyanov lftp 2.6.5

Alexander V. Lukyanov lftp 2.6.6

Alexander V. Lukyanov lftp 2.6.9

Slackware Linux 8.1

Slackware Linux 9.0

Slackware Linux 9.1

References

lftp Try_Netscape_Proxy Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report