CERT-In Vulnerability Note
CIVN-2005-0100
File Transfer Location and Tampering Vulnerability in the Windows FTP Client
Original Issue Date:October 13, 2005
Severity Rating: LOW
Systems Affected
Microsoft Windows Server 2003 for Itanium-based Systems. Microsoft Windows XP Service Pack 1. Microsoft Windows Server 2003. Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
Overview
A tempering vulnerability exists in Windows FTP client that could allow an attacker to modify the intended destination location for a file transfer.
Description
Vulnerability exists in the Windows FTP client because of the way it validates file names.
This vulnerability could allow an attacker to tamper with the file transfer location on the client during an FTP file transfer session.
Workaround
Do not download files from un-trusted FTP servers.
Solution
Apply appropriate security patches as mentioned by Microsoft security bulletin
MS05-044
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS05-044.mspx
References
AusCERT
http://www.auscert.org.au/render.html?it=5592
Nessus
http://www.nessus.org/plugins/index.php?view=single&id=19997
CVE Name
CAN-2005-2126
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|