This application requires Javascript for optimal performance.

WuFTP.Glob.Filename.Heap.Overflow

Alias(es)

WuFTP.Glob.Filename.Bad

Release Date

Aug 03, 2006

Severity

high

Impact

Attackers can execute arbitrary commands on the victim system.

Description

It indicates an attempt to exploit a heap corruption vulnerability in Washington University FTP daemon (wu-ftpd).

Wu-ftpd is a popular file transfer protocol daemon originated in Washington University. There exists a vulnerability in the globbing function that allows attackers to execute arbitrary commands via certain carefully-constructed FTP comands.

Affected Products

Any unprotected wu-ftpd 2.6.0 or 2.6.1 is vulnerable to the attack.

Recommended Actions

Upgrade to the latest non-vulnerable version of the software.




Disable anonymous FTP access unless absolutely required.



Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2001-0550

Reference/s

http://www.cert.org/advisories/CA-2001-33.html
http://www.securityfocus.com/bid/3581 (BugTraq)

Reference: VID-12093