(Vendor Issues Fix) WFTPD Memory Allocation Flaw Lets Remote Authenticated Users Deny Service
|
|
SecurityTracker Alert ID: 1009299
|
|
CVE Reference: CAN-2004-0341
(Links to External Site)
|
Updated: Mar 23 2004
|
Original Entry Date: Mar 3 2004
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Pro 3.21 Release 1
|
Description: Some denial of service vulnerabilities were reported in WFTPD. A remote authenticated user can cause the WFTPD server process to consume all available CPU resources and can cause the FTP service to crash.
axl reported that a remote authenticated user can repeatedly send a buffer longer than 512 bytes that contains characters without
an 0Ah byte to cause the FTP service to allocate additional memory and to continue to do so [CVE: CAN-2004-0341]. Eventually, the
FTP service will crash, the report said.
By generating multiple simultaneous connections in this manner, a remote authenticated
user can cause WFTPD to consume all available memory on the target system.
It is also reported that a remote authenticated user
wtih the XeroxDocutech option set to 1 ("Servers\ <ftpname>\ Users\ <username>\ XeroxDocutech" :DWORD :1) can overflow the stack
with a specially crafted MKD or XMKD FTP command [CVE: CAN-2004-0342].
The vendor has reportedly been notified.
|
Impact: A remote authenticated user can cause the WFTPD server process to consume all available CPU and memory resources on the target system.
A remote authenticated user can cause the FTP service to crash.
|
Solution: The vendor has issued a fixed version (3.21 R2), available at:
http://www.wftpd.com/downloads.htm
|
Vendor URL: www.wftpd.com/What's%20New.html#321R2Reg (Links to External Site)
|
Cause: Resource error, State error
|
Underlying OS: Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Wed, 03 Mar 2004 01:40:11 -0500
Subject: http://www.wftpd.com/What's%20New.html#321R2Reg
|
http://www.wftpd.com/What's%20New.html#321R2Reg
> Current version number: 3.21 R2
> This is a bug-fix release, fixing a remotely exploitable buffer overflow problem,
> as well as a memory starvation problem that could lead to a denial-of-service attack.
http://www.wftpd.com/downloads.htm
|
|