WU-FTPD restricted-gid Unauthorized Access Vulnerability
BID:9832
Info
WU-FTPD restricted-gid Unauthorized Access Vulnerability
| Bugtraq ID: | 9832 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0148 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2004 12:00AM |
| Updated: | Jan 25 2007 04:33PM |
| Credit: | This issue was discovered by Glenn Stewart. |
| Vulnerable: |
Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.1 Washington University wu-ftpd 2.6 .0 Washington University wu-ftpd 2.5 .0 Washington University wu-ftpd 2.4.2 academ[BETA1-15] Washington University wu-ftpd 2.4.2 academ[BETA-18] Washington University wu-ftpd 2.4.2 VR17 Washington University wu-ftpd 2.4.2 VR16 Washington University wu-ftpd 2.4.2 (beta 18) VR9 Washington University wu-ftpd 2.4.2 (beta 18) VR8 Washington University wu-ftpd 2.4.2 (beta 18) VR7 Washington University wu-ftpd 2.4.2 (beta 18) VR6 Washington University wu-ftpd 2.4.2 (beta 18) VR5 Washington University wu-ftpd 2.4.2 (beta 18) VR4 Washington University wu-ftpd 2.4.2 (beta 18) VR15 Washington University wu-ftpd 2.4.2 (beta 18) VR14 Washington University wu-ftpd 2.4.2 (beta 18) VR13 Washington University wu-ftpd 2.4.2 (beta 18) VR12 Washington University wu-ftpd 2.4.2 (beta 18) VR11 Washington University wu-ftpd 2.4.2 (beta 18) VR10 Washington University wu-ftpd 2.4.1 Sun Solaris 9_x86 Sun Solaris 9 SGI ProPack 2.4 SGI ProPack 2.3 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Compaq Tru64 5.1 b PK3(BL24) Compaq Tru64 5.1 b PK2 (BL24) Compaq Tru64 5.1 b PK2 (BL22) Compaq Tru64 5.1 b PK1 (BL1) Compaq Tru64 5.1 b Compaq Tru64 5.1 a PK6(BL24) Compaq Tru64 5.1 a PK5 (BL23) Compaq Tru64 5.1 a PK4 (BL21) Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a Avaya Interactive Response 1.3 Avaya Interactive Response 1.2.1 Avaya Interactive Response Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 13.1 |
| Not Vulnerable: | |
Discussion
WU-FTPD restricted-gid Unauthorized Access Vulnerability
WU-FTPD FTP server is reported prone to an unauthorized-access vulnerability. The issue is related to the "restricted-gid" feature supported by WU-FTPD. This feature allows an administrator to restrict FTP user access to certain directories. The vulnerability reportedly allows users to bypass those restrictions through modifying the permissions on their home directory so that they themselves can no longer access it. Under such circumstances, the server may grant the user unauthorized access to the root directory.
Further technical details are not known at this time. This record will be updated as more information becomes available.
This BID is created in response to Two Possibly New WU-FTPD Vulnerabilities BID 9820, which is being retired.
WU-FTPD FTP server is reported prone to an unauthorized-access vulnerability. The issue is related to the "restricted-gid" feature supported by WU-FTPD. This feature allows an administrator to restrict FTP user access to certain directories. The vulnerability reportedly allows users to bypass those restrictions through modifying the permissions on their home directory so that they themselves can no longer access it. Under such circumstances, the server may grant the user unauthorized access to the root directory.
Further technical details are not known at this time. This record will be updated as more information becomes available.
This BID is created in response to Two Possibly New WU-FTPD Vulnerabilities BID 9820, which is being retired.
Exploit / POC
WU-FTPD restricted-gid Unauthorized Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WU-FTPD restricted-gid Unauthorized Access Vulnerability
Solution:
Vendor updates are available. Please see the referenced vendor advisories for more information.
Sun Solaris 9
SGI ProPack 2.3
SGI ProPack 2.4
Washington University wu-ftpd 2.6.2
Compaq Tru64 5.1 a PK6(BL24)
Compaq Tru64 5.1 b PK3(BL24)
Solution:
Vendor updates are available. Please see the referenced vendor advisories for more information.
Sun Solaris 9
-
Sun 114564-09
SPARC Platform
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114564-09-1 -
Sun 114565-09
x86 Platform
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114565-09-1
SGI ProPack 2.3
-
SGI patch10062.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.3/patch1 0062.tar.gz
SGI ProPack 2.4
-
SGI patch10062.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.4/patch1 0062.tar.gz
Washington University wu-ftpd 2.6.2
-
Debian wu-ftpd-academ_2.6.2-3woody4_all.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd-academ_ 2.6.2-3woody4_all.deb -
Debian wu-ftpd_2.6.2-3woody4_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_alpha.deb -
Debian wu-ftpd_2.6.2-3woody4_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_arm.deb -
Debian wu-ftpd_2.6.2-3woody4_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_hppa.deb -
Debian wu-ftpd_2.6.2-3woody4_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_i386.deb -
Debian wu-ftpd_2.6.2-3woody4_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_ia64.deb -
Debian wu-ftpd_2.6.2-3woody4_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_m68k.deb -
Debian wu-ftpd_2.6.2-3woody4_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_mips.deb -
Debian wu-ftpd_2.6.2-3woody4_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_mipsel.deb -
Debian wu-ftpd_2.6.2-3woody4_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_powerpc.deb -
Debian wu-ftpd_2.6.2-3woody4_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_s390.deb -
Debian wu-ftpd_2.6.2-3woody4_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody4_sparc.deb -
Turbolinux wu-ftpd-2.6.2-4.i386.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/wu-ftpd-2.6.2-4.i386.rpm -
Turbolinux wu-ftpd-2.6.2-4.i386.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/wu-ftpd-2.6.2-4.i386.rpm -
Turbolinux wu-ftpd-2.6.2-4.i386.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/wu-ftpd-2.6.2-4.i386.rpm
Compaq Tru64 5.1 a PK6(BL24)
-
HP T64V51AB-IX622-WUFTPD262-SSRT4704-SSRT4705.tar
http://itrc.hp.com
Compaq Tru64 5.1 b PK3(BL24)
-
HP T64V51AB-IX622-WUFTPD262-SSRT4704-SSRT4705.tar
http://itrc.hp.com
References
WU-FTPD restricted-gid Unauthorized Access Vulnerability
References:
References:
- ASA-2006-132 - Sun Alert Notifications from Sun Weekly Report dated May 20, 2006 (Avaya)
- Avaya Communication Manager Service Packs (Avaya)
- Avaya Interactive Response: Downloads (Avaya)
- RHSA-2004:096-09 - Updated wu-ftpd package fixes security issues (RedHat)
- Sun Alert ID: 102356 - Security Vulnerability in the Solaris 9 in.ftpd(1M) Serve (Sun)