lftp Try_Squid_Eplf Buffer Overflow Vulnerability
BID:9212
Info
lftp Try_Squid_Eplf Buffer Overflow Vulnerability
| Bugtraq ID: | 9212 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0963 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovered by Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current SGI ProPack 2.4 SGI ProPack 2.3 Alexander V. Lukyanov lftp 2.6.9 Alexander V. Lukyanov lftp 2.6.8 Alexander V. Lukyanov lftp 2.6.7 Alexander V. Lukyanov lftp 2.6.6 Alexander V. Lukyanov lftp 2.6.5 Alexander V. Lukyanov lftp 2.6.4 Alexander V. Lukyanov lftp 2.6.3 Alexander V. Lukyanov lftp 2.6 .0 Alexander V. Lukyanov lftp 2.5.2 Alexander V. Lukyanov lftp 2.4.9 Alexander V. Lukyanov lftp 2.3 |
| Not Vulnerable: |
Alexander V. Lukyanov lftp 2.6.10 |
Discussion
lftp Try_Squid_Eplf Buffer Overflow Vulnerability
It has been reported that the lftp file transfer client is vulnerable to a remotely exploitable buffer overflow condition. The vulnerability is present when lftp is used to retrieve content from a remote HTTP server. According to the report, the client does not properly handle special directories that exist on the server. These failures can be exploited by operators of web servers to execute arbitrary instructions on the host running lftp. Any such code would run with the privileges of the user who invoked lftp.
** This BID, originally entitled "lftp Buffer Overflow Vulnerabilities", has been divided into two distinct issues. BID 9210 has also been revised to cover one of the issues described in the initial version of this BID.
It has been reported that the lftp file transfer client is vulnerable to a remotely exploitable buffer overflow condition. The vulnerability is present when lftp is used to retrieve content from a remote HTTP server. According to the report, the client does not properly handle special directories that exist on the server. These failures can be exploited by operators of web servers to execute arbitrary instructions on the host running lftp. Any such code would run with the privileges of the user who invoked lftp.
** This BID, originally entitled "lftp Buffer Overflow Vulnerabilities", has been divided into two distinct issues. BID 9210 has also been revised to cover one of the issues described in the initial version of this BID.
Exploit / POC
lftp Try_Squid_Eplf Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
lftp Try_Squid_Eplf Buffer Overflow Vulnerability
Solution:
The vulnerability is fixed in version 2.6.10:
http://lftp.yar.ru/get.html
A patch that applies to 2.6.9 is also available:
http://labben.abm.uu.se/~ulha9485/lftp-advisory-data.tar.gz
OpenPKG has released an advisory (OpenPKG-SA-2003.053) with fixes to address these issues. Please see the referenced advisory for further information. Fixes are linked below.
SuSE has released an advisory with fixes to address these issues. Please see the referenced advisory for more information.
RedHat has released fixes for the Fedora project. Users are advised to download the fixed packages.
Mandrake has released advisory MDKSA-2003:116 with fixes to address this issue.
Red Hat has released security advisory RHSA-2003:403-01 to address this issue. Additionally, Red Hat has released advisory RHSA-2003:404-08 to address this issue in affected Enterprise operating systems. Users are advised to run up2date to resolve this issue.
Gentoo has released advisory 200312-07 to address this issue. Affected users are advised to execute the following commands:
emerge sync
emerge -pv '>=net-ftp/lftp-2.6.10'
emerge '>=net-ftp/lftp-2.6.10'
emerge clean
Slackware have released an advisory (SSA:2003-346-01) and fixes to address this issue.
Debian has released advisory DSA 406-1 to address this issue.
Conectiva has released advisory CLA-2004:800 to address this issue.
SGI has released SGI Advanced Linux Environment security update #8 (20040101-01-U) to provide fixes for this issue. Please see the attached advisory for more details.
TurboLinux has released advisory TLSA-2004-2 to address this issue. Please see the reference section for more details.
SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below:
Slackware Linux -current
SGI ProPack 2.3
SGI ProPack 2.4
Alexander V. Lukyanov lftp 2.4.9
Alexander V. Lukyanov lftp 2.5.2
Alexander V. Lukyanov lftp 2.6 .0
Alexander V. Lukyanov lftp 2.6.3
Alexander V. Lukyanov lftp 2.6.4
Alexander V. Lukyanov lftp 2.6.5
Alexander V. Lukyanov lftp 2.6.6
Alexander V. Lukyanov lftp 2.6.9
Slackware Linux 8.1
Slackware Linux 9.0
Slackware Linux 9.1
Solution:
The vulnerability is fixed in version 2.6.10:
http://lftp.yar.ru/get.html
A patch that applies to 2.6.9 is also available:
http://labben.abm.uu.se/~ulha9485/lftp-advisory-data.tar.gz
OpenPKG has released an advisory (OpenPKG-SA-2003.053) with fixes to address these issues. Please see the referenced advisory for further information. Fixes are linked below.
SuSE has released an advisory with fixes to address these issues. Please see the referenced advisory for more information.
RedHat has released fixes for the Fedora project. Users are advised to download the fixed packages.
Mandrake has released advisory MDKSA-2003:116 with fixes to address this issue.
Red Hat has released security advisory RHSA-2003:403-01 to address this issue. Additionally, Red Hat has released advisory RHSA-2003:404-08 to address this issue in affected Enterprise operating systems. Users are advised to run up2date to resolve this issue.
Gentoo has released advisory 200312-07 to address this issue. Affected users are advised to execute the following commands:
emerge sync
emerge -pv '>=net-ftp/lftp-2.6.10'
emerge '>=net-ftp/lftp-2.6.10'
emerge clean
Slackware have released an advisory (SSA:2003-346-01) and fixes to address this issue.
Debian has released advisory DSA 406-1 to address this issue.
Conectiva has released advisory CLA-2004:800 to address this issue.
SGI has released SGI Advanced Linux Environment security update #8 (20040101-01-U) to provide fixes for this issue. Please see the attached advisory for more details.
TurboLinux has released advisory TLSA-2004-2 to address this issue. Please see the reference section for more details.
SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below:
Slackware Linux -current
-
Slackware lftp-2.6.10-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/lf tp-2.6.10-i486-1.tgz
SGI ProPack 2.3
-
SGI patch10040.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.3/patch1 0040.tar.gz
SGI ProPack 2.4
-
SGI patch10044.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.4/patch1 0044.tar.gz
Alexander V. Lukyanov lftp 2.4.9
-
Debian lftp_2.4.9-1woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _alpha.deb -
Debian lftp_2.4.9-1woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _arm.deb -
Debian lftp_2.4.9-1woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _hppa.deb -
Debian lftp_2.4.9-1woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _ia64.deb -
Debian lftp_2.4.9-1woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _m68k.deb -
Debian lftp_2.4.9-1woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _mips.deb -
Debian lftp_2.4.9-1woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _powerpc.deb -
Debian lftp_2.4.9-1woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _s390.deb -
Debian lftp_2.4.9-1woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/l/lftp/lftp_2.4.9-1woody2 _sparc.deb -
RedHat lftp-2.4.9-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/lftp-2.4.9-2.i386.rpm -
RedHat lftp-2.4.9-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/lftp-2.4.9-2.i386.rpm -
RedHat lftp-2.4.9-2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/lftp-2.4.9-2.ia64.rpm
Alexander V. Lukyanov lftp 2.5.2
-
RedHat lftp-2.5.2-6.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/lftp-2.5.2-6.i386.rpm
Alexander V. Lukyanov lftp 2.6 .0
-
Mandrake lftp-2.6.0-1.1.90mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lftp-2.6.0-1.1.C21mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lftp-2.6.0-1.1.C21mdk.x86_64.rpm
Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Alexander V. Lukyanov lftp 2.6.3
-
RedHat lftp-2.6.3-4.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/lftp-2.6.3-4.i386.rpm
Alexander V. Lukyanov lftp 2.6.4
-
Mandrake lftp-2.6.4-2.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lftp-2.6.4-2.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG lftp-2.6.4-1.2.1.src.rpm
ftp://ftp.openpkg.org/release/1.2/UPD/lftp-2.6.4-1.2.1.src.rpm -
SuSE lftp-2.6.4-44.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/lftp-2.6.4-44.i58 6.patch.rpm -
SuSE lftp-2.6.4-44.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/lftp-2.6.4-44.i58 6.rpm
Alexander V. Lukyanov lftp 2.6.5
-
Fedora lftp-2.6.10-1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /lftp-2.6.10-1.i386.rpm -
Fedora lftp-debuginfo-2.6.10-1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/lftp-debuginfo-2.6.10-1.i386.rpm
Alexander V. Lukyanov lftp 2.6.6
-
Mandrake lftp-2.6.6-2.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lftp-2.6.6-2.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG lftp-2.6.6-1.3.1.src.rpm
ftp://ftp.openpkg.org/release/1.3/UPD/lftp-2.6.6-1.3.1.src.rpm -
SuSE lftp-2.6.6-71.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/lftp-2.6.6-71.i58 6.patch.rpm -
SuSE lftp-2.6.6-71.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/lftp-2.6.6-71.i58 6.rpm -
TurboLinux lftp-2.6.11-1.i386.rpm
TurboLinux Advanced Server 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/lftp-2.6.11-1.i386.rpm -
TurboLinux lftp-2.6.11-1.i386.rpm
TurboLinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/lftp-2.6.11-1.i386.rpm -
TurboLinux lftp-2.6.11-1.i386.rpm
TurboLinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/lftp-2.6.11-1.i386.rpm -
TurboLinux lftp-2.6.11-1.i586.rpm
TurboLinux Desktop 10.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/lftp-2.6.11-1.i586.rpm -
TurboLinux lftp-2.6.11-1.i586.rpm
TurboLinux Server 7.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/lftp-2.6.11-1.i586.rpm -
TurboLinux lftp-2.6.11-1.i586.rpm
TurboLinux Server 8.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/lftp-2.6.11-1.i586.rpm -
TurboLinux lftp-2.6.11-1.i586.rpm
TurboLinux Workstation 7.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/lftp-2.6.11-1.i586.rpm -
TurboLinux lftp-2.6.11-1.i586.rpm
TurboLinux Workstation 8.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/lftp-2.6.11-1.i586.rpm
Alexander V. Lukyanov lftp 2.6.9
-
Conectiva lftp-2.6.9-1U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/lftp-2.6.9-1U80_2cl.i386.rp m -
Conectiva lftp-2.6.9-23261U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/lftp-2.6.9-23261U90_2cl.i38 6.rpm -
RedHat lftp-2.4.9-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/lftp-2.4.9-2.i386.rpm -
RedHat lftp-2.4.9-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/lftp-2.4.9-2.i386.rpm -
RedHat lftp-2.4.9-2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/lftp-2.4.9-2.ia64.rpm
Slackware Linux 8.1
-
Slackware lftp-2.6.10-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/l ftp-2.6.10-i386-1.tgz
Slackware Linux 9.0
-
Slackware lftp-2.6.10-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/l ftp-2.6.10-i386-1.tgz
Slackware Linux 9.1
-
Slackware lftp-2.6.10-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/l ftp-2.6.10-i486-1.tgz
References
lftp Try_Squid_Eplf Buffer Overflow Vulnerability
References:
References:
- [VulnWatch] lftp buffer overflows (Harnhammar, Ulf
) - LFTP Homepage (LFTP)
- RHSA-2003:404-08 - Updated lftp packages fix security vulnerability (RedHat)
- TLSA-2004-2 lftp (TurboLinux)