Critical security hole in the wu-ftpd server
Summary
In 2003 Janusz Niewiadomski published a buffer overflow in the FTP server wu-ftpd, versions 2.5.0 to 2.6.2, on Bugtraq. The function fb_realpath() mishandled paths longer than 4096 bytes; anyone with write access who was allowed to create directories could exploit it. The major distributions delivered updates; as a workaround, prohibiting new directories with “upload … nodirs” helped.
Ideas
- Overlong path names overwrote the FTP server’s stack.
- Writable directories such as /incoming made the attack possible.
- Whether a binary was vulnerable depended on the PATH_MAX of the kernel it was built under.
- Distributors were informed before publication.
Insights
- Anonymous write access considerably enlarges a service’s attack surface.
- Build environment and platform constants can decide whether a hole is exploitable.
Facts
- wu-ftpd from 2.5.0 to 2.6.2 on x86 was affected.
- Red Hat, SUSE, Debian and Mandrake already responded with updates at publication.
References
Critique
- The report briefly explains the PATH_MAX dependency, but not how administrators can check their own binary.
Remarks
- Even then wu-ftpd was considered error-prone and was later largely replaced by vsftpd and other servers; FTP itself is giving way to SFTP today.
Recommendations
- Replace classic FTP with SFTP or FTPS with tightly restricted write access.
- Prohibit creating subdirectories in upload directories if it is not needed.
Links to the original source and the Web Archive open in a new tab.