[Full-disclosure] Crob FTP Server remote buffer overflows

From: Leon Juranic (ljuranic_at_lss.hr)
Date: 06/06/05

  • Next message: ZATAZ Audits: "[Full-disclosure] Cisco pix 501 - 5.5 PPTP VPN"
    Date: Mon,  6 Jun 2005 11:58:49 +0200 (CEST)
    To: undisclosed-recipients: ;
    
    

                                    LSS Security Advisory #LSS-2005-06-06
                                             http://security.lss.hr

     
    Title: Crob FTP Server remote buffer overflows
    Advisory ID: LSS-2005-06-06
    Date: 2005-06-01
    Advisory URL: http://security.lss.hr/index.php?page=details&ID=LSS-2005-06-06
    Impact: Remote code execution
    Risk Level: High
    Vulnerability Type: Remote
    Vendors Status: 7th March, 2005

     
    ==[ Overview
     
    Crob FTP Server is a powerful and flexible FTP Server with full user management
    and network control for Windows 95/98/ME/2000/XP/2003. Crob FTP Server is using
    the standard FTP (File Transfer Protocol) protocol an can be downloaded from
    http://www.crob.net/en/.
     

    ==[ Vulnerability

    There are various buffer overflows in Crob FTP server when processing client input.
    First vulnerability is the stack overflow that can be triggered with a very long
    parameter supplied to arbitrary FTP command (i.e. STOR) and calling RMD command
    with long parameter afterwards. As a result, EIP is overflowed with user input.
    Second vulnerability is the heap overflow vulnerability, probably in globbing
    code, which can be triggered with characters like '?' or '*' followed by a long
    string. This vulnerability can be triggered with commands like LIST or NLST.
    Sucessful exploitation of these vulnerabilities will lead to remote code execution.

     
    ==[ Affected Version

    Vulnerabilities were discovered in the latest Crob FTP server 3.6.1, but the
    older versions might be also vulnerable.

     
    ==[ Fix

    No fix available yet.

     
    ==[ PoC Exploit
     
    Proof of concept code can be downloaded at http://security.lss.hr/PoC

     
    ==[ Credits
     
    Credits for this vulnerability goes to Leon Juranic <ljuranic@lss.hr>.

     
    ==[ LSS Security Contact
     
    LSS Security Team,

    WWW : http://security.lss.hr
    E-mail : security@LSS.hr
    Tel : +385 1 6129 775

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: ZATAZ Audits: "[Full-disclosure] Cisco pix 501 - 5.5 PPTP VPN"

    Relevant Pages

    • Format String Vulnerability in Crob Ftp Server
      ... Vulnerability: Format String ... A format string flaw in the authentication process allows remote attackers ... without valid user/pass to execute arbitrary code. ... 220 Welcome to Crob FTP Server ...
      (Bugtraq)
    • SecurityFocus Microsoft Newsletter #445
      ... MICROSOFT VULNERABILITY SUMMARY ... Apple Safari CoreGraphics TrueType Font Handling Remote Code Execution Vulnerability ... Microsoft Windows Argument Validation Local Privilege Escalation Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #313
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Class Package Export Tool Clspack.exe Local Buffer Overflow Vulnerability ... Microsoft PowerPoint Unspecified Remote Unspecified Code Execution Vulnerability ... Microsoft Office Malformed Record Remote Code Execution Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #299
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Excel File Rebuilding Remote Code Execution Vulnerability ... Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #295
      ... MICROSOFT VULNERABILITY SUMMARY ... Sendmail Malformed MIME Message Denial Of Service Vulnerability ... Microsoft Windows Routing and Remote Access Unspecified Remote Code Execution Vulnerability ...
      (Focus-Microsoft)

  • Quantcast