WU-FTPD MAIL_ADMIN configuration SockPrintf buffer overflow
| wuftp-mailadmin-sockprintf-bo (13269) |
Description:
Washington University's FTP daemon (WU-FTPD) is vulnerable to a buffer overflow in the SockPrintf function in the ftpd.c file, if the server is compiled with the MAIL_ADMIN option, which is not the default configuration. A remote attacker, with file upload privileges, could upload a large file to overflow a buffer and possibly execute arbitrary code on the system with privileges of the WU-FTPD process.
Platforms Affected:
- Washington University, WU-FTPD 2.5
- Washington University, WU-FTPD 2.6.0
- Washington University, WU-FTPD 2.6.1
- Washington University, WU-FTPD 2.6.2
Remedy:
For Slackware Linux:
Refer to the slackware-security Mailing List posting dated Tue, 23 Sep 2003 23:07:06 -0700 (PDT) for patch or upgrade information. See References.
Consequences:
Gain Access
References:
- BugTraq Mailing List, Mon Sep 22 2003 - 07:44:16 CDT, Wu_ftpd all versions (not) vulnerability. at http://archives.neohapsis.com/archives/bugtraq/2003-09/0348.html.
- slackware-security Mailing List, Tue, 23 Sep 2003 23:07:06 -0700 (PDT), WU-FTPD Security Advisory (SSA:2003-259-03) at http://www.slackware.org/security/viewer.php?l=slackware-security&y=2003&m=slackware-security.365971.
- WU-FTPD Development Group Web site, WU-FTPD Development Group at http://www.wu-ftpd.org/.
- BID-8668: Wu-Ftpd SockPrintf() Remote Stack-based Buffer Overrun Vulnerability
- CVE-2003-1327: Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.
- OSVDB ID: 2594: WU-FTPD MAIL_ADMIN Function Remote Overflow
- SA9835: WU-FTPD "MAIL_ADMIN" Buffer Overflow Vulnerability
- SECTRACK ID: 1007775: wu-ftpd MAIL_ADMIN Option May Let Remote Authenticated Users Execute Arbitrary Code
Reported:
Sep 22, 2003
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
