[UNIX] ProFTPD Long Password Crash
From: support@securiteam.com
Date: 12/25/02
- Previous message: support@securiteam.com: "[NEWS] Multiple Buffer overruns RealNetworks Helix Universal Server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: 25 Dec 2002 11:49:22 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
Beyond Security would like to welcome Tiscali World Online
to our service provider team.
For more info on their service offering IP-Secure,
please visit http://www.worldonline.co.za/services/work_ip.asp
- - - - - - - - -
ProFTPD Long Password Crash
------------------------------------------------------------------------
SUMMARY
There appears to be a bug in ProFTPD version 1.5.2 and RC versions, the
bug exists in the login process of the daemon. Specifically in the
password authentication. After the client has connected to the remote host
and sends the login username whether be a legit or anonymous, if the user
then issues the "PASS" command with 12 Kilobytes of data or more as the
password, the daemon will crash.
DETAILS
Vulnerable systems:
* ProFTPD version 1.5.2 and RC
Demonstration:
telnet 127.0.0.1 21
Connected!
user burnx
pass iwatch@porn@<12k+ Buffer>
ADDITIONAL INFORMATION
The information has been provided by BuRn-X.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Next message: support@securiteam.com: "[UNIX] printenv XSS Vulnerability"
- Previous message: support@securiteam.com: "[NEWS] Multiple Buffer overruns RealNetworks Helix Universal Server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|