[NT] Windows XP SP2 TFTP Client Local Buffer Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 10/06/05

  • Next message: SecuriTeam: "[NT] ALZip Multiple Archive Handling Buffer Overflow"
    To: list@securiteam.com
    Date: 6 Oct 2005 14:48:49 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Windows XP SP2 TFTP Client Local Buffer Overflow
    ------------------------------------------------------------------------

    SUMMARY

    TFTP stands for Trivial File Transfer Protocol. Network application that
    is simpler than the File Transfer Protocol (FTP) but less capable. TFTP
    built on UDP.

    The TFTP client provided with Windows XP (tftp.exe) is vulnerable to a
    locally exploitable heap overflow.

    DETAILS

    Vulnerable Systems:
     * Windows XP - TFTP.EXE version 5.1.2600.0 (xpclient.010817-1148)

    The Windows XP tftp.exe software is vulnerable to a Heap Based overflow,
    allowing to run arbitrary commands on the system as the user issuing the
    overflow. The registers EAX and ECX are controlled, by sending 1446 bytes
    of crap or payload and then the next 8 bytes are the EAX and ECX.

    Proof of concept:
    tftp -i 127.0.0.1 GET
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    <snip>CCCCBBBB

    Disclosure Timeline:
     * 01.08.05 - Vulnerability discovered
     * 15.08.05 - Research completed
     * 19.08.05 - Vendor notified
     * 19.08.05 - Security vulnerability tagged tftp [6167bgs] at Microsoft
     * 08.09.05 - Microsoft responds with an timeframe of fix - See Corrective
    actions
     * 03.10.05 - Public release

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:advisory@cirt.dk> Dennis
    Rand.
    The original article can be found at:
    <http://www.cirt.dk/advisories/cirt-38-advisory.pdf>
    http://www.cirt.dk/advisories/cirt-38-advisory.pdf

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] ALZip Multiple Archive Handling Buffer Overflow"

    Relevant Pages

    • [NT] Winamp ID3v2 Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Winamp is vulnerable to a buffer overflow vulnerability when processing ... control the EAX register, ...
      (Securiteam)
    • [NT] Citrix Program Neighborhood Name Heap Corruption
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Citrix Program Neighborhood Name Heap Corruption ... Exploitation of a heap overflow vulnerability in Citrix, ...
      (Securiteam)
    • [NT] PacketTrap TFTP Server Denial of Service
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in the way pt360's TFTP ... int timeout; ... if local_file is equal to %s will be used stdout for upload or ...
      (Securiteam)
    • [NT] Novell eDirectory Multiple Vulnerabilities (dhost.exe)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Novell eDirectory Core Protocol Opcode 0x24 Heap Overflow Vulnerability ...
      (Securiteam)
    • [NT] IBM Tivoli Provisioning Manager for OS Deployment Multiple Stack Overflow Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... IBM Tivoli Provisioning Manager for OS Deployment Multiple Stack Overflow ... A vulnerability allows remote attackers to execute arbitrary code on ...
      (Securiteam)