|
Brought to you by:
Suppliers of:
|
|
|
| |
Serv-U is a "powerful, easy-to-use, award-winning FTP server" created by Rob Beckers.
The popular Windows FTP server contains a buffer overflow condition when processing the MDTM command. A logged user can send a malformed timezone argument to the MDTM command and invoke the vulnerability. A specially crafted argument will allow the user to gain SYSTEM privileges. |
| |
Credit:
The information has been provided by bkbll.
|
| |
Vulnerable Systems:
* Serv-U version 5.0
Immune Systems:
* Serv-U version 5.0.0.4
After a successful login, a user may enter the following (or equivalent) command:
MDTM 20031111111111+AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA /test.txt
Of course, one has to log in to the FTP server before the vulnerability can be exploited. However, no special privileges, such as write permissions, are needed in order to exploit the vulnerability. In fact, the test.txt file itself doesn't even have to exist on the server. It is enough to send a long MDTM command to the server.
Patch Availability:
The vendor has been contacted and a new version of Serv-U FTP is available. It is highly advisable to upgrade to version 5.0.0.4.
|
|
|
|
|