bk99.de entertain the web since 1997

Critical security hole in the wu-ftpd server

Summary

In 2003 Janusz Niewiadomski published a buffer overflow in the FTP server wu-ftpd, versions 2.5.0 to 2.6.2, on Bugtraq. The function fb_realpath() mishandled paths longer than 4096 bytes; anyone with write access who was allowed to create directories could exploit it. The major distributions delivered updates; as a workaround, prohibiting new directories with “upload … nodirs” helped.

Ideas

  • Overlong path names overwrote the FTP server’s stack.
  • Writable directories such as /incoming made the attack possible.
  • Whether a binary was vulnerable depended on the PATH_MAX of the kernel it was built under.
  • Distributors were informed before publication.

Insights

  • Anonymous write access considerably enlarges a service’s attack surface.
  • Build environment and platform constants can decide whether a hole is exploitable.

Facts

  • wu-ftpd from 2.5.0 to 2.6.2 on x86 was affected.
  • Red Hat, SUSE, Debian and Mandrake already responded with updates at publication.

References

Critique

  • The report briefly explains the PATH_MAX dependency, but not how administrators can check their own binary.

Remarks

  • Even then wu-ftpd was considered error-prone and was later largely replaced by vsftpd and other servers; FTP itself is giving way to SFTP today.

Recommendations

  • Replace classic FTP with SFTP or FTPS with tightly restricted write access.
  • Prohibit creating subdirectories in upload directories if it is not needed.

Read the original article

Search the Web Archive