Samhain Labs HSFTP Remote Format String Vulnerability
BID:9715
Info
Samhain Labs HSFTP Remote Format String Vulnerability
| Bugtraq ID: | 9715 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0159 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 23 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery of this issue has been credited to Ulf Harnhammar. |
| Vulnerable: |
Samhain Labs hsftp 1.14 Samhain Labs hsftp 1.13 Samhain Labs hsftp 1.11 Samhain Labs hsftp 1.10 Samhain Labs hsftp 1.9 Samhain Labs hsftp 1.7 Samhain Labs hsftp 1.6 Samhain Labs hsftp 1.5 Samhain Labs hsftp 1.4 hsftp hsftp 1.14 hsftp hsftp 1.13 hsftp hsftp 1.11 hsftp hsftp 1.10 hsftp hsftp 1.9 hsftp hsftp 1.7 hsftp hsftp 1.6 hsftp hsftp 1.5 hsftp hsftp 1.4 |
| Not Vulnerable: | |
Discussion
Samhain Labs HSFTP Remote Format String Vulnerability
hsftp has been found to be prone to a remote print format string vulnerability. This issue is due to the application improper use of a format printing function.
Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected software, which would occur in the security context of the server process.
hsftp has been found to be prone to a remote print format string vulnerability. This issue is due to the application improper use of a format printing function.
Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected software, which would occur in the security context of the server process.
Exploit / POC
Samhain Labs HSFTP Remote Format String Vulnerability
Exploit code has been provided by priestmaster <[email protected]>.
Exploit code has been provided by priestmaster <[email protected]>.
Solution / Fix
Samhain Labs HSFTP Remote Format String Vulnerability
Solution:
The vendor has reportedly addressed this issue in the upstream version 1.14.
Debian has released advisory DSA 447-1 dealing with this issue. Please see the reference section for more details.
Fixes:
Samhain Labs hsftp 1.11
hsftp hsftp 1.11
Solution:
The vendor has reportedly addressed this issue in the upstream version 1.14.
Debian has released advisory DSA 447-1 dealing with this issue. Please see the reference section for more details.
Fixes:
Samhain Labs hsftp 1.11
-
Debian hsftp_1.11-1woody1_alpha.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_alpha.deb -
Debian hsftp_1.11-1woody1_arm.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_arm.deb -
Debian hsftp_1.11-1woody1_hppa.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_hppa.deb -
Debian hsftp_1.11-1woody1_i386.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_i386.deb -
Debian hsftp_1.11-1woody1_ia64.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_ia64.deb -
Debian hsftp_1.11-1woody1_m68k.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_m68k.deb -
Debian hsftp_1.11-1woody1_mips.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_mips.deb -
Debian hsftp_1.11-1woody1_powerpc.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_powerpc.deb -
Debian hsftp_1.11-1woody1_s390.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_s390.deb -
Debian hsftp_1.11-1woody1_sparc.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_sparc.deb
hsftp hsftp 1.11
-
Debian hsftp_1.11-1woody1_alpha.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_alpha.deb -
Debian hsftp_1.11-1woody1_arm.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_arm.deb -
Debian hsftp_1.11-1woody1_hppa.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_hppa.deb -
Debian hsftp_1.11-1woody1_i386.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_i386.deb -
Debian hsftp_1.11-1woody1_ia64.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_ia64.deb -
Debian hsftp_1.11-1woody1_m68k.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_m68k.deb -
Debian hsftp_1.11-1woody1_mips.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_mips.deb -
Debian hsftp_1.11-1woody1_powerpc.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_powerpc.deb -
Debian hsftp_1.11-1woody1_s390.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_s390.deb -
Debian hsftp_1.11-1woody1_sparc.deb
http://security.debian.org/pool/updates/main/h/hsftp/hsftp_1.11-1woody 1_sparc.deb