RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
BID:9274
Info
RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
| Bugtraq ID: | 9274 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 22 2003 12:00AM |
| Updated: | Dec 22 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Squ4L1 Squ4L1 <[email protected]>. |
| Vulnerable: |
Rhino Software Serv-U 4.1 Rhino Software Serv-U 4.0 .0.4 Rhino Software Serv-U 3.1 Rhino Software Serv-U 3.0 |
| Not Vulnerable: | |
Discussion
RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
RhinoSoft Serv-U FTP Server has been reported prone to an insecure file permission vulnerability. Specifically, a configuration file is created with insecure permissions by default. Because of this any local user may make modifications to the file and ultimately may exploit this condition to gain elevated privileges.
It should be noted that although this vulnerability has been reported to affect RhinoSoft Serv-U FTP Server version 4.1.0.0, other versions might also be affected.
RhinoSoft Serv-U FTP Server has been reported prone to an insecure file permission vulnerability. Specifically, a configuration file is created with insecure permissions by default. Because of this any local user may make modifications to the file and ultimately may exploit this condition to gain elevated privileges.
It should be noted that although this vulnerability has been reported to affect RhinoSoft Serv-U FTP Server version 4.1.0.0, other versions might also be affected.
Exploit / POC
RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
RhinoSoft Serv-U FTP Server Insecure INI File Permissions Vulnerability
References:
References:
- Serv-U Homepage (RhinoSoft)