The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Fri, 18 May 2001 13:03:22 +0300
From: Tamer Sahin <feedback@tamersahin.net>
To: bugtraq@securityfocus.com
Subject: Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability


Tamersahin.net Security Announcement
DEBIAN 2.2 is 2.2r3 FTPD DAEMON BUFFER OWERFLOW
Release Date: ========== May 18, 2001 Severity: ======= High. Systems Affected: ============== Debian 2.2 is 2.2r3 default ftpd daemon Version 6.2/OpenBSD/Linux-0.10. Concept: ======= The vulnerability arises when a buffer of aprox. 400 bytes and more is sent within the ftpd daemon running Debian host header for a SITE request. Example: ======= May 18 12:32:46 ts ftpd[677]: ts FTP server (Version 6.2/OpenBSD/Linux-0.10) ready. May 18 12:32:47 ts ftpd[677]: command: SITE AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA May 18 12:32:47 ts ftpd[677]: <--- 500 May 18 12:32:47 ts ftpd[677]: 'SITE AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA': command not understood. May 18 12:32:47 ts ftpd[677]: <--- 221 May 18 12:32:47 ts ftpd[677]: You could at least say goodbye. May 18 12:32:47 ts inetd[139]: ftp/tcp server failing (looping), service terminated Exploit Code: ========== Not yet. Author: ====== Tamer Sahin http://www.tamersahin.net feedback@tamersahin.net Copyright (c) 1995-2001 tamersahin.net

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру