|
Family: FTP --> Category: mixed
ProFTPd pre6 buffer overflow Vulnerability Scan
Vulnerability Scan Summary Checks if the remote ftp can be buffer overflown
Detailed Explanation for this Vulnerability Test
It was possible to make the remote FTP server
crash by issuing this command :
NLST aaaXXXX%u%[...]%u%u%u%%u%653300u%n
Where XXXX have ascii values 0xDC, 0x4F, 0x07 and 0x08.
This problem is known has the 'proftpd pre6' overflow and
may allow the remote user to gain root easily.
Solution : if you are using proftpd, then upgrade
to proftpd 1.2.0pre7. If you are using something else,
then upgrade or contact your vendor.
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|