[ advisories | exploits | discussions | news | conventions | security tools | texts & papers ]
 main menu
- feedback
- advertising
- privacy
- FightAIDS
- newsletter
- news
 
 discussions
- read forum
- new topic
- search
 

 meetings
- meetings list
- recent additions
- add your info
 
 top 100 sites
- visit top sites
- sign up now
- members
 
 webmasters

- add your url
- add domain
- search box
- link to us

 
 projects
- our projects
- free email
 
 m4d network
- security software
- secureroot
- m4d.com
Home : Advisories : OS/2 Warp 4.5 FTP Server DoS

Title: OS/2 Warp 4.5 FTP Server DoS
Released by: Vigilante
Date: 15th August 2000
Printable version: Click here
OS/2 Warp 4.5 FTP Server DoS



Advisory Code:   VIGILANTE-2000006



Release Date:

August 15, 2000



Systems Affected:

-      OS/2 Warp 4.5 FTP server V4.0/4.2

- OS/2 Warp 4.5 FTP server V4.3

- Probably  other versions of the software as well.



THE PROBLEM

The FTP server that comes with OS/2 Warp 4.5 TCP/IP can be brought down by a

malicious connection attempt.



Vendor Status:

The vendor has released the patch for the problem and it contains

the following explanation of the problem: "Sending username/password

followed immediately by up to 1k of data when connecting to FTP via Telnet,

can cause a trap. ".

During testing we found that an initial connection attempt (using sockets,

telnet, ftp) using an invalid username/password combination, followed by a

second attempt, where the userfield was exceptionally long (256 bytes) would

crash the service.



Fix:

In case you are using a version prior to 4.3, please contact IBM support for

further assistance.

If you are using v4.3, you can get the patch at the following URL:

http://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/



Vendor   URL: http://www.ibm.com

Product  URL: http://www.ibm.com/software/os/warp/



Copyright VIGILANTe 2000-08-15



Disclaimer:

The information within this document may change without notice. Use of

this information constitutes acceptance for use in an AS IS

condition. There are NO warranties with regard to this information.

In no event shall the author be liable for any consequences whatsoever

arising out of or in connection with the use or spread of this

information. Any use of this information lays within the user's

responsibility.



Feedback:

Please send suggestions, updates, and comments to:



VIGILANTe

mailto: info@vigilante.com

http://www.vigilante.com














(C) 1999-2000 All rights reserved.