Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

FTP:COMMAND:WS-FTP-REST

Severity

Major

Recommended

No

Recommended Action

Drop

Category

FTP

Keywords

WS-FTP REST Command Large File Creation

Release Date

2011/06/14

Update Number

1937

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

FTP: WS-FTP REST Command Large File Creation


This signature detects attempts to exploit a known vulnerability against WS-FTP. A successful attack can lead to arbitrary code execution within the context of the application.

Extended Description

Multiple vulnerabilities have been identified in the WS_FTP Server and client applications. These vulnerabilities may allow remote attackers to execute arbitrary code, cause denial of service attacks and gain administrative level access to a server. The issues include two remote buffer overflow vulnerabilities in the client, a denial of service vulnerability in the server and an access validation issue in the server leading to remote command execution with SYSTEM privileges. These issues are undergoing further analysis. This BID will be divided into separate issues as analysis is completed.

Affected Products

  • Ipswitch ws_ftp_pro 6.0.0
  • Ipswitch ws_ftp_pro 7.5.0
  • Ipswitch ws_ftp_pro 8.0.0 2
  • Ipswitch ws_ftp_pro 8.0.0 3
  • Ipswitch ws_ftp_server 1.0.1
  • Ipswitch ws_ftp_server 1.0.2
  • Ipswitch ws_ftp_server 1.0.3
  • Ipswitch ws_ftp_server 1.0.4
  • Ipswitch ws_ftp_server 1.0.5
  • Ipswitch ws_ftp_server 2.0.0
  • Ipswitch ws_ftp_server 2.0.1
  • Ipswitch ws_ftp_server 2.0.2
  • Ipswitch ws_ftp_server 2.0.3
  • Ipswitch ws_ftp_server 2.0.4
  • Ipswitch ws_ftp_server 3.0.0
  • Ipswitch ws_ftp_server 3.0.0 1
  • Ipswitch ws_ftp_server 3.1.0
  • Ipswitch ws_ftp_server 3.1.1
  • Ipswitch ws_ftp_server 3.1.2
  • Ipswitch ws_ftp_server 3.1.3
  • Ipswitch ws_ftp_server 3.4.0
  • Ipswitch ws_ftp_server 4.0.0
  • Ipswitch ws_ftp_server 4.0.0 1
  • Ipswitch ws_ftp_server 4.0.0 2

References

  • BugTraq: 9953
  • CVE: CVE-2004-1885

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out