AppleFileServer AFP PathName buffer overflow
| applefileserver-afp-pathname-bo (16049) |
Description:
AppleFileServer (AFS) is vulnerable to a stack-based buffer overflow. If AFP is enabled, which is not the default setting, a remote attacker could send a LoginExt packet containing a specially-crafted PathName argument to overflow a buffer and execute arbitrary commands on the system with root privileges.
Consequences:
Gain Access
Remedy:
Apply the appropriate patch for your system, available from the Apple Web site. See References.
References:
- @stake, Inc. Security Advisory a050304-1: AppleFileServer Remote Command Execution .
- Apple Computer, Inc.Web site: Apple.
- CIAC Information Bulletin O-138: Apple Mac OS X Jaguar and Panther Security Vulnerabilities.
- CIAC Information Bulletin O-139: Apple Mac OS X AppleFileServer Authentication Vulnerability.
- Mac OS X Server Web page: Mac OS X Server.
- Mac OS X Web page: Apple - Mac OS X.
- BID-10271: Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulnerability
- CVE-2004-0430: Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.
- SA11539: Mac OS X Security Update Fixes Multiple Vulnerabilities
- SECTRACK ID: 1010039: AppleFileServer Buffer Overflow in Processing Cleartext User Authentication Method Packets Lets Remote Users Execute Code With Root Privileges
- US-CERT VU#648406: Apple Mac OS X AppleFileServer fails to properly handle certain authentication requests
Platforms Affected:
- Apple Mac OS X 10.0
- Apple Mac OS X 10.0.4
- Apple Mac OS X 10.1
- Apple Mac OS X 10.1.1
- Apple Mac OS X 10.1.2
- Apple Mac OS X 10.1.3
- Apple Mac OS X 10.1.4
- Apple Mac OS X 10.1.5
- Apple Mac OS X 10.2
- Apple Mac OS X 10.2.1
- Apple Mac OS X 10.2.2
- Apple Mac OS X 10.2.3
- Apple Mac OS X 10.2.4
- Apple Mac OS X 10.2.5
- Apple Mac OS X 10.2.6
- Apple Mac OS X 10.2.7
- Apple Mac OS X 10.2.8
- Apple Mac OS X 10.3
- Apple Mac OS X 10.3.1
- Apple Mac OS X 10.3.2
- Apple Mac OS X 10.3.3
- Apple Mac OS X Server 10.0
- Apple Mac OS X Server 10.0.1
- Apple Mac OS X Server 10.0.2
- Apple Mac OS X Server 10.0.3
- Apple Mac OS X Server 10.1
- Apple Mac OS X Server 10.1.1
- Apple Mac OS X Server 10.1.2
- Apple Mac OS X Server 10.1.3
- Apple Mac OS X Server 10.1.4
- Apple Mac OS X Server 10.1.5
- Apple Mac OS X Server 10.2
- Apple Mac OS X Server 10.2.1
- Apple Mac OS X Server 10.2.2
- Apple Mac OS X Server 10.2.3
- Apple Mac OS X Server 10.2.4
- Apple Mac OS X Server 10.2.5
- Apple Mac OS X Server 10.2.6
- Apple Mac OS X Server 10.2.7
- Apple Mac OS X Server 10.2.8
- Apple Mac OS X Server 10.3
- Apple Mac OS X Server 10.3.1
- Apple Mac OS X Server 10.3.2
- Apple Mac OS X Server 10.3.3
Reported:
May 03, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
