GEN:SID | 1:2344 |
Message | FTP XCWD overflow attempt |
Summary | This event is generated when an attempt is made to exploit a known vulnerability in ArGoSoft FTP Server.
|
Impact | Execution of arbitrary code. Possible unauthorized administrative access.
|
Detailed Information | ArGoSoft FTP Server fails to perform sufficient checks on user supplied data to the XCWD command. An attacker may exploit this vulnerability to execute code of their choosing as the user running the process. This may lead to remote administrative access to the server.
|
Affected Systems | ArGoSoft FTP Server 1.4.1 .1
|
Attack Scenarios | An attacker may connect to the server and supply spurious data to the XCWD command causing the overrun to occur.
|
Ease of Attack | Simple.
|
Corrective Action | Apply the appropriate vendor supplied patches.
Upgrade to the latest non-affected version of the software.
|
Additional References | |
Rule References | bugtraq: 11542
bugtraq: 8704
|