ArGoSoft FTP Server Multiple Vulnerabilities
BID:9770
Info
ArGoSoft FTP Server Multiple Vulnerabilities
| Bugtraq ID: | 9770 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2004 12:00AM |
| Updated: | Feb 27 2004 12:00AM |
| Credit: | Discovery of these issues is credited to STORM of Beyond Security. |
| Vulnerable: |
ArGo Software Design FTP Server 1.4.1 .5 ArGo Software Design FTP Server 1.4.1 .4 ArGo Software Design FTP Server 1.4.1 .3 ArGo Software Design FTP Server 1.4.1 .2 ArGo Software Design FTP Server 1.4.1 .1 ArGo Software Design FTP Server 1.2.2 .2 ArGo Software Design FTP Server 1.0 |
| Not Vulnerable: |
ArGo Software Design FTP Server 1.4.1 .6 |
Discussion
ArGoSoft FTP Server Multiple Vulnerabilities
ArGoSoft has released version 1.4.1.6 of their FTP Server to address multiple unspecified security vulnerabilities. These issues include three buffer overruns when handling overly long FTP SITE ZIP and SITE COPY commands, a file enumeration issue involving the SITE UNZIP command and user database corruption denial of service attacks via the SITE PASS command.
ArGoSoft has released version 1.4.1.6 of their FTP Server to address multiple unspecified security vulnerabilities. These issues include three buffer overruns when handling overly long FTP SITE ZIP and SITE COPY commands, a file enumeration issue involving the SITE UNZIP command and user database corruption denial of service attacks via the SITE PASS command.
Exploit / POC
ArGoSoft FTP Server Multiple Vulnerabilities
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
ArGoSoft FTP Server Multiple Vulnerabilities
Solution:
These issues have been addressed in version 1.4.1.6 of ArGoSoft FTP Server.
ArGo Software Design FTP Server 1.0
ArGo Software Design FTP Server 1.2.2 .2
ArGo Software Design FTP Server 1.4.1 .4
ArGo Software Design FTP Server 1.4.1 .2
ArGo Software Design FTP Server 1.4.1 .3
ArGo Software Design FTP Server 1.4.1 .5
ArGo Software Design FTP Server 1.4.1 .1
Solution:
These issues have been addressed in version 1.4.1.6 of ArGoSoft FTP Server.
ArGo Software Design FTP Server 1.0
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.2.2 .2
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.4.1 .4
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.4.1 .2
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.4.1 .3
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.4.1 .5
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
ArGo Software Design FTP Server 1.4.1 .1
-
ArGoSoft FTP Server 1.4.1.6
http://www.argosoft.com/applications/ftpserver/download.asp
References
ArGoSoft FTP Server Multiple Vulnerabilities
References:
References:
- ArGoSoft FTP Server Change List (ArGoSoft)
- ArGoSoft FTP Server Multiple Vulnerabilities (SITE ZIP, UNZIP, COPY, PASS) (Securiteam)
- ArGoSoft FTP Server Product Home Page (ArGoSoft)