N-156: ProFTPD ASCII File Remote Compromise Vulnerability
Privacy and Legal Notice
INFORMATION BULLETIN
N-156: ProFTPD ASCII File Remote Compromise Vulnerability
September 30, 2003 13:00 GMT
|
| PROBLEM: |
A flaw in the ProFTPD Unix FTP server ASCII file upload component can cause a buffer overflow and give a remote intruder root access.
|
| PLATFORM: |
ProFTPD 1.2.7, 1.2.8, 8rc1, 8rc2, 9rc1, 9rc2
|
| DAMAGE: |
A buffer overflow and give a remote intruder root access.
|
| SOLUTION: |
Apply patch for the ProFTPD vulnerability.
|
|
VULNERABILITY
ASSESSMENT: |
The risk is HIGH. A remote intruder can get root access if anonymous uploading is allowed. Authenticated users can get root if anonymous ulploading is not allowed.
|
|
Due to ISS copyright restrictions, CIAC is only able to provide a link to ISS's bulletin.
For more information, visit:
http://xforce.iss.net/xforce/alerts/id/154
CIAC wishes to acknowledge the contributions of Internet Security Systems X-Force for the
information contained in this bulletin.
CIAC services are available to DOE, DOE Contractors, and the NIH. CIAC
can be contacted at:
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org
This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.
UCRL-MI-119788
[Privacy and Legal Notice]