Executive brief
A vulnerability exists in the file transfer services used by wu-ftpd and BSDI systems to handle remote file management. An attacker can exploit a timing flaw during the execution of specific commands to bypass security controls. If successful, this allows the attacker to take full control of the server with administrative (root) privileges, potentially leading to data theft or complete system compromise.
Technical details
A race condition exists in the implementation of the SITE EXEC command within wu-ftpd and BSDI ftpd. The vulnerability is triggered when a remote attacker issues a SITE EXEC request, which allows for the execution of external programs on the server. Due to improper synchronization or timing flaws during the command execution process, an attacker can manipulate the execution environment to escalate privileges. Successful exploitation grants the attacker root-level access to the underlying operating system. This is a network-based attack that does not necessarily require prior authentication depending on the FTP configuration.
Affected products
- Washington University wu-ftpd
- BSDI ftpd
Timeline
- 1997-09-23: disclosed