SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (File Transfer/Sharing)  >   ProFTPD Vendors:   ProFTPd
ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1007794
SecurityTracker URL:  http://securitytracker.com/id/1007794
CVE Reference:   CAN-2003-0831   (Links to External Site)
Updated:  Sep 26 2003
Original Entry Date:  Sep 23 2003
Impact:   Execution of arbitrary code via network, Root access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): Confirmed on 1.2.7, 1.2.8, 1.2.8rc1, 1.2.8rc2, 1.2.9rc1, and 1.2.9rc2
Description:   A buffer overflow vulnerability was reported in the ProFTPD FTP server. A remote user with upload privileges may be able to obtain root access on the target system.

Internet Security Systems reported that there is a flaw in the processing of inbound ASCII file transfers. A remote user with upload privileges can upload a specially crafted file in ASCII mode and then attempt to download the file to trigger the buffer overflow and execute arbitrary code. The remote user can bypass ProFTPD security checks to cause the code to execute with root level privileges, the report said.

According to the report, the flaw resides in the translation of newline characters.

The CVE number CAN-2003-0831 has been assigned to this issue.

Impact:   A remote user with file upload privileges can execute arbitrary code on the target system with root privileges.
Solution:   The vendor has issued a fixed version (1.2.9rc2p), available at:

ftp://ftp.proftpd.org/distrib/source/proftpd-1.2.9rc2p.tar.gz
ftp://ftp.proftpd.org/distrib/source/proftpd-1.2.9rc2p.tar.bz2

Vendor URL:  www.proftpd.org/ (Links to External Site)
Cause:   Boundary error
Underlying OS:   Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Sep 25 2003 (Slackware Issues Fix) ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Slackware Security Team <security@slackware.com>)
Slackware has released a fix.
Sep 27 2003 (Mandrake Issues Fix) ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a fix.
Sep 30 2003 (Trustix Issues Fix) Re: ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Trustix Secure Linux Advisor <tsl@trustix.com>)
Trustix has issued a fix.
Oct 1 2003 (Conectiva Issues Fix) ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Conectiva Updates <secure@conectiva.com.br>)
Conectiva has released a fix.
Oct 13 2003 (Exploit Code is Available) Re: ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Carl Livitt <carl@learningshophull.co.uk>)
Additional exploit code is available.
Oct 17 2003 (TurboLinux Issues Fix) Re: ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Turbolinux <security-announce@turbolinux.co.jp>)
TurboLinux has issued a fix.
Jan 2 2004 (Mandrake Issues Revised Fix) ProFTPD ASCII Mode File Upload Buffer Overflow Lets Certain Remote Users Execute Arbitrary Code   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a revised fix.



 Source Message Contents

Date:  Tue, 23 Sep 2003 10:53:26 -0400 (EDT)
Subject:  ISS Security Brief: ProFTPD ASCII File Remote Compromise Vulnerability


-----BEGIN PGP SIGNED MESSAGE-----

Internet Security Systems Security Brief
September 23, 2003

ProFTPD ASCII File Remote Compromise Vulnerability
 
Synopsis:

ISS X-Force has discovered a flaw in the ProFTPD Unix FTP server. ProFTPD
is a highly configurable FTP (File Transfer Protocol) server for Unix
that allows for per-directory access restrictions, easy configuration of 
virtual FTP servers, and support for multiple authentication mechanisms.
A flaw exists in the ProFTPD component that handles incoming ASCII file
transfers.

Impact:

An attacker capable of uploading files to the vulnerable system can
trigger a buffer overflow and execute arbitrary code to gain complete
control of the system. Attackers may use this vulnerability to destroy,
steal, or manipulate data on vulnerable FTP sites.

Affected Versions:

ProFTPD 1.2.7
ProFTPD 1.2.8
ProFTPD 1.2.8rc1
ProFTPD 1.2.8rc2
ProFTPD 1.2.9rc1
ProFTPD 1.2.9rc2

Note: Versions previous to version 1.2.7 may also be vulnerable.

For the complete ISS X-Force Security Advisory, please visit: 
http://xforce.iss.net/xforce/alerts/id/154

______ 

About Internet Security Systems (ISS) 
Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a 
pioneer and world leader in software and services that protect critical 
online resources from an ever-changing spectrum of threats and misuse. 
Internet Security Systems is headquartered in Atlanta, GA, with 
additional operations throughout the Americas, Asia, Australia, Europe 
and the Middle East. 

Copyright (c) 2003 Internet Security Systems, Inc. All rights reserved 
worldwide. 

Permission is hereby granted for the electronic redistribution of this 
document. It is not to be edited or altered in any way without the 
express written consent of the Internet Security Systems X-Force. If you 
wish to reprint the whole or any part of this document in any other 
medium excluding electronic media, please email xforce@iss.net for 
permission. 

Disclaimer: The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS 
condition. There are NO warranties, implied or otherwise, with regard to 
this information or its use. Any use of this information is at the 
user's risk. In no event shall the author/distributor (Internet Security 
Systems X-Force) be held liable for any damages whatsoever arising out 
of or in connection with the use or spread of this information. 
X-Force PGP Key available on MIT's PGP key server and PGP.com's key server, 
as well as at http://www.iss.net/security_center/sensitive.php 
Please send suggestions, updates, and comments to: X-Force 
xforce@iss.net of Internet Security Systems, Inc. 

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBP3BeFTRfJiV99eG9AQG2ngP/XopPpEYCbR6HSYhObaK+c2D32kwfiQEP
CJqXmoljU661kBKvL2RclLF8tutegL3T44/5utBuVgzCWALSRrJiJgZMWafRtE7m
lnl7V5Rzo7aEBxhmiaOqdLoNgzNd8NTtSkPrcFQZxjrQe9FvpIgsyiuY6ADNoDfH
mXStpCwCFWg=
=TZR3
-----END PGP SIGNATURE-----

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC