nwlogo
NAVIGATION
About
News
Support

Downloads
- Search
- Mirrors
- Auto update

Documentation
- FAQ
- HOWTOs
- ARM info
- Crusoe info

Development
- Toolchain
- Autobuild
- Users

Sponsored by:

Open Source Lab at OSU

LaneChange.net

NetWinder security advisory
ID2000-009
Issued2000-Jun-25
Packagewu-ftpd
SummaryBuffer overflow in wu-ftpd
CategoryBuffer overflow
SeverityHigh (remote root compromise)
ProductsDeveloper dm-3.1-15 and earlier
OfficeServer os-1.5-4 and earlier

DESCRIPTION

A remotely-exploitable vulnerability has been found in the "wu-ftpd" package. Specifically the command "SITE EXEC" is can overflow its buffer leading to compromise.

The "wu-ftpd" package provides FTP server functionality and is enabled by default on the Developer and OfficeServer products.

SOLUTION

Download the following RPM packages to the NetWinder into a temporary directory, then install them with the command "rpm -Uvh *.rpm". Be sure there are no other files ending in ".rpm" in the temporary directory. See http://www.netwinder.org/security/install.html for more help.

Required packages

http://www.netwinder.org/updates/3.1-15/armv4l/wu-ftpd-2.6.0-14.6x.armv4l.rpm

REFERENCES

Reported on Red Hat's bugtraq on June 23, 2000.