Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> FTP >> WS_FTP SITE CPWD Buffer Overflow


Vulnerability Assessment Details

WS_FTP SITE CPWD Buffer Overflow

Vulnerability Assessment Summary
Checks FTP server banner for vulnerable version of WS_FTP Server

Detailed Explanation for this Vulnerability Assessment

This host is running a version of WS_FTP FTP server prior to 3.1.2.
Versions earlier than 3.1.2 contain an unchecked buffer in routines that
handle the 'CPWD' command arguments. The 'CPWD' command permits remote
users to change their password. By issuing a malformed argument to the
CPWD command, a user could overflow a buffer and execute arbitrary code
on this host. Note that a local user account is required.

The vendor has released a patch that fixes this issue. Please install
the latest patch available from the vendor's website at
http://www.ipswitch.com/support/.

Network Security Threat Level: High

Networks Security ID: 5427

Vulnerability Assessment Copyright: This script is Copyright (C) 2002 Digital Defense, Inc.

Cables, Connectors

Dell PowerEdge E01S Polycom CMA 4000 1 Intel Xeon E5506 @ 2.13GHz 8GB RAM
$218.98
Dell PowerEdge E01S Polycom CMA 4000 1 Intel Xeon E5506 @ 2.13GHz 8GB RAM pictureAxion A0763342-AX Axiom 4GB DDR2 SDRAM Memory Module - 4GB (1 x 4GB) - 667MHz DD
$45.32
Axion A0763342-AX Axiom 4GB DDR2 SDRAM Memory Module - 4GB (1 x 4GB) - 667MHz DD pictureSamsung Chromebook 11.6 Laptop 1.7GHz, 2GB Ram, 16GB SSD, XE303C12 WITH CHARGER
$51.47
Samsung Chromebook 11.6 Laptop 1.7GHz, 2GB Ram, 16GB SSD, XE303C12 WITH CHARGER pictureAxion AXG17991287/1 Axiom 4GB FBDIMM Module TAA Compliant - 4 GB - DDR2 SDRAM -
$46.6
Axion AXG17991287/1 Axiom 4GB FBDIMM Module TAA Compliant - 4 GB - DDR2 SDRAM - picture


Discussions

No Discussions have been posted on this vulnerability.