[NT] BlackJumboDog FTP Server Buffer Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 08/01/04

  • Next message: SecuriTeam: "[UNIX] OpenFTPD Format String Vulnerability"
    To: list@securiteam.com
    Date: 1 Aug 2004 15:20:52 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      BlackJumboDog FTP Server Buffer Overflow
    ------------------------------------------------------------------------

    SUMMARY

    SapporoWorks BlackJumboDog is an integrated open-source proxy server, web
    server and FTP server developed by SapporoWorks for Microsoft Windows
    platforms.

    BlackJumboDog version 3.6.1 is vulnerable to a buffer overflow in its FTP
    server.

    DETAILS

    Vulnerable Systems:
     * BlackJumboDog version 3.6.1

    Immune Systems:
     * BlackJumboDog version 3.6.2

    Impact:
    By sending a specially crafted FTP request containing a long parameter
    string in the USER, PASS, RETR, CWD, XMKD, XRMD or various other commands,
    a remote attacker could cause a stack overflow and execute arbitrary code.

    Technical Details:
    This vulnerability is caused by an unsafe strcpy() that copies the entire
    parameter of the user's FTP command to a stack buffer of 256 bytes. For
    example, suppose that the user's FTP client issues the following command.
    USER xxxxxxxxxxxx

    The command parameter "xxxxxxxxxxxx" will be copied to a 256 bytes buffer
    using strcpy(). Hence, by crafting an FTP command with an overly long
    parameter, a remote attacker could trigger a stack overflow and execute
    arbitrary code. The attacker do not need to have a valid account on the
    FTP server since the overflow can be triggered prior to authentication
    using the USER command.

    Vendor Status:
    The author has fixed the bug in version 3.6.2. Users are advised to
    upgrade to the fixed version.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:chewkeong@security.org.sg>
    Chew Keong TAN.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] OpenFTPD Format String Vulnerability"

    Relevant Pages

    • Re: FTP PUT with Store Unique
      ... The best list for topics related to the Communications Server IP ... command or vice versa. ... Instructs the FTP client not to include a name with the STOU ... -- If NONAME is in effect, no name string specifying a foreign_file value follows ...
      (bit.listserv.ibm-main)
    • [NT] Orenosv HTTP/FTP Server Multiple Buffer Overflows
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Mutliple buffer overflows vulnerabilities were found in Orenosv's server. ... These buffer overflow is triggered when the server receives a FTP ... Long SSI Command Buffer Overflow Vulnerability: ...
      (Securiteam)
    • Re: FTP Error 426
      ... This command tells the server to abort the previous FTP ... Out-of-band data may be used for whatever purpose an application may have for it. ...
      (bit.listserv.ibm-main)
    • Re: Some questions
      ... > using my ftp software behind my router. ... > issued to server by the client. ... When PORT is used: ... > Can you give me a command line used in a browser to explain me what is the ...
      (comp.security.firewalls)
    • [NT] Microsoft wininet.dll FTP Reply Null Termination Heap Corruption Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption ... Windows Server 2003 Enterprise Edition SP1 ... This vulnerability appears to have existed from at least Internet ...
      (Securiteam)

  • Quantcast