TNFTPD < 20040811 Globbing Overflow

medium Nessus Network Monitor Plugin ID 3836

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The remote host is running TNFTPD, a port of the NetBSD FTP daemon. This version of TNFTPD is vulnerable to a remote buffer overflow. The flaw is within the glob.c function. An attacker exploiting this flaw would need to authenticate to the server and then pass a malformed string that would be interpreted by the glob function. Successful exploitation results in the attacker executing arbitrary code on the remote system.

Solution

Upgrade to version 20040811 or higher.

Plugin Details

Severity: Medium

ID: 3836

Family: FTP Servers

Published: 12/1/2006

Updated: 3/6/2019

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:ND

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.7

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:X

Vulnerability Information

CPE: cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*

Reference Information

CVE: CVE-2006-6652

BID: 21377