Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 200403-08 ] oftpd DoS vulnerability
Date: Mon, 29 Mar 2004 15:22:54
Message-Id: 20040329152000.GN24315@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200403-08
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: oftpd DoS vulnerability
9 Date: March 29, 2004
10 Bugs: #45738
11 ID: 200403-08
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A remotely-exploitable overflow exists in oftpd, allowing an attacker
19 to crash the oftpd daemon.
20
21 Background
22 ==========
23
24 Quote from http://www.time-travellers.org/oftpd/
25
26 "oftpd is designed to be as secure as an anonymous FTP server can
27 possibly be. It runs as non-root for most of the time, and uses the
28 Unix chroot() command to hide most of the systems directories from
29 external users - they cannot change into them even if the server is
30 totally compromised! It contains its own directory change code, so that
31 it can run efficiently as a threaded server, and its own directory
32 listing code (most FTP servers execute the system "ls" command to list
33 files)."
34
35 Affected packages
36 =================
37
38 -------------------------------------------------------------------
39 Package / Vulnerable / Unaffected
40 -------------------------------------------------------------------
41 net-ftp/oftpd <= 0.3.6 >= 0.3.7
42
43 Description
44 ===========
45
46 Issuing a port command with a number higher than 255 causes the server
47 to crash. The port command may be issued before any authentication
48 takes place, meaning the attacker does not need to know a valid
49 username and password in order to exploit this vulnerability.
50
51 Impact
52 ======
53
54 This exploit causes a denial of service.
55
56 Workaround
57 ==========
58
59 While a workaround is not currently known for this issue, all users are
60 advised to upgrade to the latest version of the affected package.
61
62 Resolution
63 ==========
64
65 All users should upgrade to the current version of the affected
66 package:
67
68 # emerge sync
69
70 # emerge -pv ">=net-ftp/oftpd-0.3.7"
71 # emerge ">=net-ftp/oftpd-0.3.7"
72
73 References
74 ==========
75
76 [ 1 ] http://www.time-travellers.org/oftpd/oftpd-dos.html
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.