TNFTPD < 20040811 Globbing Overflow

Medium Nessus Network Monitor Plugin ID 3836

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The remote host is running TNFTPD, a port of the NetBSD FTP daemon. This version of TNFTPD is vulnerable to a remote buffer overflow. The flaw is within the glob.c function. An attacker exploiting this flaw would need to authenticate to the server and then pass a malformed string that would be interpreted by the glob function. Successful exploitation results in the attacker executing arbitrary code on the remote system.

Solution

Upgrade to version 20040811 or higher.

Plugin Details

Severity: Medium

ID: 3836

File Name: 3836.prm

Family: FTP Servers

Published: 2006/12/01

Modified: 2016/02/05

Dependencies: 1803, 1804, 3222

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:ND

CVSSv3

Base Score: 6.2

Temporal Score: 5.5

Vector: CVSS3#AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:P/RL:O/RC:X

Reference Information

CVE: CVE-2006-6652

BID: 21377