Re: ISSalert: ISS Security Alert: WU-FTPD Heap Corruption Vulnerability (fwd)

From: Igor Roshchin (str@giganda.komkon.org)
Date: 12/01/01


Date: Sat, 1 Dec 2001 14:05:15 -0500 (EST)
From: Igor Roshchin <str@giganda.komkon.org>
To: freebsd-security@FreeBSD.ORG, kheuer@gwdu60.gwdg.de, venglin@freebsd.lublin.pl


> From: Przemyslaw Frasunek <venglin@freebsd.lublin.pl>
> Date: Sat, 1 Dec 2001 12:25:44 +0100
>
> On Friday 30 November 2001 09:53, Konrad Heuer wrote:
> > Any opinions whether wu-ftpd on FreeBSD is vulnerable too? To my mind, it
> > seems so.
>
> actually, wu-ftpd on FreeBSD is vulnerable, but phk-malloc design prevents
> from exploiting this. typical scenario of exploitation on linux box is:
>

Actually, ;-)
AFAICT, the wu-ftpd port has been patched by the maintainer (ache).
AFAICT, Patches from Wu-FTPD were incorporated.

In any case, thanks Przemyslaw for the detailed analysis.

Igor

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Wu-Ftpd
    ... > i have the standard ftp server when i login with my username ... You should know that wu-ftpd is not the "standard" ftp server on ... FreeBSD comes with a ftp server in the base system. ...
    (FreeBSD-Security)
  • Re: Wu-ftpd FTP server contains remotely exploitable off-by-one bug
    ... > I see in BugTraq that there's yet another problem with Wu-ftpd, ... > reason to assume that FreeBSD machines aren't vulnerable, ... Buffer overflows which work on Linux do not work on FreeBSD. ...
    (FreeBSD-Security)
  • Re: Need an advice...
    ... And which FTP server I must use? ... As for FTPd: if you don't need the feature bloat, proftpd and wu-ftpd ... provide, I suggest to stick with ftpd since for that one, FreeBSD ...
    (FreeBSD-Security)
  • Re: Wu-ftpd FTP server contains remotely exploitable off-by-one bug
    ... > I see in BugTraq that there's yet another problem with Wu-ftpd, ... > reason to assume that FreeBSD machines aren't vulnerable, ... If you want to bitch at someone, bitch at the wu-ftpd.org guys for ...
    (FreeBSD-Security)
  • Re: ftp was hacked
    ... Right now I wouldn't trust WU-FTPd. ... >]a sniffer and a port scanner on my machine. ... >]A few days later I wanted to install a later version of hdparm. ... > patches. ...
    (comp.os.linux.security)