SpoonFTP Buffer Overflow Vulnerabilities

From: SNS Research (vuln-devat_private)
Date: Wed May 30 2001 - 12:55:58 PDT

  • Next message: Immunix Security Team: "Immunix OS Security update for man"

    Strumpf Noir Society Advisories
    ! Public release !
    <--#
    
    
    -= SpoonFTP Buffer Overflow Vulnerabilities =-
    
    Release date: Thursday, May 31, 2001
    
    
    Introduction:
    
    SpoonFTP is an ftp server from the hand of the makers of SpoonProxy
    for the various MS Windows incarnations.
    
    SpoonFTP is available from vendor Pi-Soft's website:
    http://www.pi-soft.com
    
    
    Problem(s):
    
    The SpoonFTP server doesn't correctly apply boundary checks on 
    the 'CWD' and 'LIST' commands. Issueing one of these to the server 
    followed by respectively 530 and 531 bytes of data or more will 
    cause the server to die.
    
    Altough in the majority of the attempts internal errors will kill
    the SpoonFTP process before any data can be passed on to the stack,
    it is possible to use this to overwrite eip and execute arbitrary
    code on the target machine.
    
    
    (..)
    
    
    Solution:
    
    Vendor has been notified and has verified the existence of these
    problems. SpoonFTP v1.0.0.13 has been released to deal with them. 
    Users are encouraged to upgrade.
    
    This was tested against SpoonFTP v1.0.0.12 on Win2k.
    
    
    yadayadayada
    
    Free sk8! (http://www.freesk8.org)
    
    SNS Research is rfpolicy (http://www.wiretrip.net/rfp/policy.html) 
    compliant, all information is provided on AS IS basis.
    
    EOF, but Strumpf Noir Society will return!
    



    This archive was generated by hypermail 2b30 : Wed May 30 2001 - 18:23:57 PDT