FTP Server 'glob' Function Overflow

Critical Nessus Network Monitor Plugin ID 1836

Synopsis

The remote host is vulnerable to a globbing overflow.

Description

It may be possible to make the remote FTP server crash by creating a large directory structure and then attempting to list it using wildcards. This is usually known as the 'ftp glob overflow' attack. An attacker can use this flaw to execute arbitrary code on the remote server, which could lead to remote shell access.

Solution

Upgrade your FTP server and/or libc. Consider removing directories writable by 'anonymous'.

See Also

http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html

http://ftp://patches.sgi.com/support/free/security/advisories/20010802-01-P

http://www.openbsd.org/errata28.html#glob_limit

Plugin Details

Severity: Critical

ID: 1836

File Name: 1836.prm

Family: FTP Servers

Published: 2004/08/20

Modified: 2016/01/19

Dependencies: 1803, 1804, 3222

Nessus ID: 10648

Risk Information

Risk Factor: Critical

CVSSv2

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2001-0247

BID: 2548

OSVDB: 537