OSVDB ID: 13248

Title: Winmail Server FTP Server PORT Command Bounce Attack

Info

Disclosure

Jan 27, 2005

Discovery

Jan 15, 2005

Dates

Exploit

Unknown

Solution

Unknown

Description

Winmail Server contains a flaw that may lead to an unauthorized information disclosure. The problem is that the FTP server does not validate IP addresses supplied via the PORT command. It is possible for a remote attacker to establish a connection between the server and an arbitrary port on another system to perform a portscan, which will disclose sensitiv system information resulting in a loss of confidentiality.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 4.0 (Build 1318) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

AMAX Information Technologies Inc.

Winmail Server

4.0 (Build 1112)

References

Credit

  • Tan Chew Keong - vulnBrand New Doo Doosecunia.com - Secunia Research


Direct URL: http://osvdb.org/36218