A remote overflow exists in wu-ftpd. A SockPrintf call in ftpd.c fails to properly check bounds on a pathname when wu-ftpd is compiled with MAIL_ADMIN enabled resulting in a buffer overflow. With a specially crafted request, an attacker can possibly execute arbitrary code as the user wu-ftpd runs as (usually root) resulting in a loss of integrity, and/or availability.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Technical
It should be noted that this vulnerability may not be exploitable on most systems. It relies on creating a very long file name (greater than 32778 bytes), but on many systems, it is not possible to create a file name that long.
Solution
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): do not compile wu-ftpd with MAIL_ADMIN defined/enabled (by default, MAIL_ADMIN is not defined).
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.