OSVDB ID: 8994

Title: Heimdal ftpd Signal Handling Privilege Escalation

Info

Disclosure

Aug 18, 2004

Discovery

Unknown

Dates

Exploit

Aug 22, 2004

Solution

Unknown

Description

Multiple ftpd contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to improper signal handler operations. By providing a USER command during an established FTP session, a remote attacker could gain access to unauthorized privileges, resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Race Condition
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 0.6.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Heimdal

Heimdal ftpd

0.6.2

References

Credit

  • Przemyslaw Frasunek - venglinfreebsd.lublin.pl - Przemyslaw Frasunek


Direct URL: http://osvdb.org/8994