|
|
|
Vulnerability Note VU#110803
CrushFTP Server does not adequately filter user input thereby permitting directory traversal
OverviewCrushFTP allows access to files outside the FTP root directory through directory traversal.
I. DescriptionCrushFTP is a Java-based FTP server available for Linux, Mac OS, and Windows. CrushFTP can be configured to limit access to files under a designated FTP root directory. However, CrushFTP allows an attacker to get files outside this directory through '../' directory traversal.II. ImpactCrushFTP allows an attacker to see any file in the filesystem, including potentially sensitive and critical system files.III. SolutionUpgrade to version 2.1.7 or later of CrushFTP at:
http://www.crushftp.com
Use chroot if available on your system, to limit the scope of CrushFTP's access to the filesystem.
Systems Affected
| Vendor | Status | Date Updated |
| Ben Spink | Vulnerable | 17-Nov-2001 |
References
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2001-0583
http://xforce.iss.net/static/6495.php
http://xforce.iss.net/alerts/vol-6_num-7.php
Credit
Thanks to Joe Testa for discovering this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
| Date Public | 05/23/2001 09:24:54 AM |
| Date First Published | 12/20/2001 11:50:12 AM |
| Date Last Updated | 12/20/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0582 |
| Metric | 0.11 |
| Document Revision | 12 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |