[NT] Dynu FTP Server Directory Traversal Vulnerability
From: support@securiteam.comDate: 08/22/01
- Previous message: support@securiteam.com: "[NEWS] Viewing Someone's Hotmail Account in Three Easy Steps"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Subject: [NT] Dynu FTP Server Directory Traversal Vulnerability Message-Id: <20010822055955.3F9AA138BF@mail.der-keiler.de> Date: Wed, 22 Aug 2001 07:59:55 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Dynu FTP Server Directory Traversal Vulnerability
------------------------------------------------------------------------
SUMMARY
<http://www.dynu.com/dynuftpserver.asp> Dynu FTP Server is a
multithreaded FTP server supporting the RFC 959 protocol completely.
Features include support for multi-homed servers, user access management,
active log and much more. A security vulnerability in the product allows
attackers to traverse outside the normal bounding FTP root directory and
read arbitrary files on the system.
DETAILS
Vulnerable systems:
Dynu FTP Server version 1.05 and prior
Immune systems:
Dynu FTP Server version 1.06
By simply issuing a "cwd .." (cd ..) will get you one directory above the
chained root directory.
Solution:
Upgrade to the latest version 1.06.
ADDITIONAL INFORMATION
The information has been provided by
<mailto:Christoph.Heindl@fhs-hagenberg.ac.at> Christoph.Heindl.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Viewing Someone's Hotmail Account in Three Easy Steps"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|