27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

Platinum FTP server Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 1825 FAMILY: FTP Servers RISK: HIGH NESSUS ID:11200<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nPlatinum FTP<br />

server for Win32 has several vulnerabilities in the way it checks the format of command<br />

strings passed to it. This leads to the following vulnerabilities in the server: The 'dir'<br />

command can be used to examine the filesystem of the machine and gather further<br />

information about the host by using relative directory listings (I.E. '../../../' or '\..\..\..'). The<br />

'delete' command can be used to delete any file on the server that the Platinum FTP server<br />

has permissions to. Issuing the command 'cd @/..@/..' will cause the Platinum FTP server<br />

to crash and consume all available CPU time on the server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

NiteServer < 1.85 FTP Server Traversal Directory Listing<br />

<strong>PVS</strong> ID: 1826 FAMILY: FTP Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11466<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw which allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote FTP server allows anybody to switch to the root<br />

directory and read potentially sensitive files.<br />

Solution: Upgrade to version 1.85 or higher.<br />

CVE-2003-1349<br />

AIX FTPd libc Library Remote Overflow<br />

<strong>PVS</strong> ID: 1827 FAMILY: FTP Servers RISK: HIGH NESSUS ID:10009<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nIt is possible to make<br />

the remote FTP server crash by issuing this command : CEL aaaa[...]aaaa. This problem is<br />

known as the 'AIX FTPd' overflow and may allow the remote user to easily gain access to<br />

the root (super-user) account on the remote system.<br />

Solution: See IBM's advisory number ERS-SVA-E01-1999:004.1 or contact your vendor for a patch.<br />

CVE-1999-0789<br />

bftpd < 1.0.14 chown Command Overflow<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 1828 FAMILY: FTP Servers RISK: HIGH NESSUS ID:10579<br />

Family Internet Services 464

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!