robinbhandari FTP 安全漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1532155 漏洞类型 输入验证错误
发布时间 2019-03-13 更新时间 2020-01-13
CVE编号 CVE-2019-9668 CNNVD-ID CNNVD-201903-473
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019030110
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201903-473
|漏洞详情
robinbhandari FTP是一款FTP(文件传输协议)客户端和服务器。 robinbhandari FTP 2012-03-28及之前版本中存在拒绝服务漏洞。远程攻击者可利用该漏洞造成拒绝服务。
|漏洞EXP
Title: CVE-2019-9668 robinbhandari FTP remote DoS vulnerability

Vulnerable:
- https://github.com/rovinbhandari/FTP

Description:
robinbhandari is a open source tiny ftp server/client in github.com.
it has a remote DoS vulnerability in a 'put' command.

Timeline:
2019-03-11 CVE-2019-9668 robinbhandari FTP remote DoS vulnerability.
2019-03-10 my personal site advisory published.
2019-03-09 request CVE to mitre. (Report).
2019-02-27 vulnerability found.

Details:
hacker can set packet struct's datalen field variable. which is recv size from server side file transferring.
then If set 0xffff(size of unsigned short) to datalen, put ./file then server side error occured and
server will be closed.

Vulnerable code:
--------------------
FTP/file_transfer_functions.c
[...]
void receive_file(struct packet* hp, struct packet* data, int sfd, FILE* f)
{
[...]
        int x;
        int i = 0, j = 0;

        // (1) recved packet from ftp client.
        if((x = recv(sfd, data, size_packet, 0)) <= 0)
                er("recv()", x);
        j++;

        // (2) hp = struct packet * fields parsing.
        hp = ntohp(data);
        //printpacket(hp, HP);
        while(hp->type == DATA) // (3) If DATA type then enter here..
        {
                i += fwrite(hp->buffer, 1, hp->datalen, f);     // (4) x90c:: hacker can set hp->datalen, then server daemon error then remote DoS result occured.

                if((x = recv(sfd, data, size_packet, 0)) <= 0)
                        er("recv()", x);
                j++;
                hp = ntohp(data);
                //printpacket(hp, HP);
        }
[...]
--------------------

PoC:
we can change client_ftp.c to compile.

Credit:
x90c <x90chacker@gmail.com> - http://www.x90chacker.org.

|参考资料

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/152058/robinbhandari-FTP-Remote-Denial-Of-Service.html