A bug in the Kerberos4 ftp client may cause heap overflow which leads to remote code execution

From: Marcell Fodor (m.fodor@mail.datanet.hu)
Date: 04/24/02


Date: 24 Apr 2002 20:13:23 -0000
From: Marcell Fodor <m.fodor@mail.datanet.hu>
To: bugtraq@securityfocus.com


('binary' encoding is not supported, stored as-is)

Kerberos4 ftp client is a simple ftp client, with the
extensions defined by RFC 2228.
When authentication fails with AUTH, client will use
USER/PASS command as other ones.

A bug in the code may cause a heap overflow which leads to
remote code execution.
The overflow occurs when the server responds to client's
request for passive mode. If the server
responds with a long reply in the place of IP and port,
pasv buffer will overflow.

Affected version: 4-1.1.1

The real danger: an ftp server can simply modified to
recognize Kerberos4 ftp client by it's protocol. You know
the rest.

Details and exploit code: mantra.freeweb.hu

Marcell Fodor



Relevant Pages

  • Attn. Microsoft - BUG REPORT!
    ... Methinks Microsoft's web server would meltdown if ... Bug 1: Windows XP Pro Updater hangs when updating from ... but WinXP FTP client hangs. ...
    (microsoft.public.windowsxp.general)
  • Re: Upload of large files hangs at CWD command
    ... Occasionally hangs on the FTP client (and we use several - IE, ... Microsoft Windows Server 2003, Standard Edition, SP1 ... > When a user uploads a large file to the server, they report it gets ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: FTP from "My Network Places" to server?
    ... Microsoft MVP FrontPage ... "David Seguin" wrote in message ... The staging server has FP ... > FTP client to ftp from stg to prod. ...
    (microsoft.public.frontpage.client)
  • Spped of FreeWare FTP-Server under WinXP?
    ... I just tested the overall transfere speed of 2 FreeWare FTPds ... with ftp client Total Commander 6.54a) and 125 MB jpg pics ... which Server ist the fastest? ... TotalCommander - Cerberos: ...
    (microsoft.public.windows.server.networking)
  • [UNIX] Kerberos4 FTP Client Found to Contain a Heap Overflow
    ... Kerberos4 FTP client is a simple FTP client, ... A vulnerability in the code allows ... A bug in the code may cause a heap overflow that would lead to remote code ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)