Short Name |
FTP:COMMAND:3CDAEMON-PATH-DISCL |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
FTP |
Keywords |
3CDaemon Path Disclosure |
Release Date |
2006/10/18 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against FTP 3CDaemon. Attackers can use the 3CDaemon to disclose information; for example, a full path.
3CDaemon is reportedly prone to multiple vulnerabilities. These issues may allow an attacker to crash the application, disclose sensitive information, and potentially execute arbitrary code on a vulnerable computer. The following specific issues were identified: Multiple format string vulnerabilities are reported to affect the application. These issues may allow an attacker to cause a denial of service condition or write to arbitrary process memory and potentially execute code. Multiple buffer overflow vulnerabilities affect the application as well. These issues may allow remote attackers to execute arbitrary code on a vulnerable computer or crash the application. 3CDaemon also discloses sensitive information when a request for certain MS-DOS device names is carried out. This type of sensitive information may be used in further attacks against the computer. 3CDaemon 2.0 revision 10 is reported prone to these vulnerabilities, however, other versions may also be affected.