RealSecure Server Sensor, RealSecure Desktop Protector, RealSecure Network, BlackICE Agent for Server, RealSecure Guard, RealSecure Sentry, BlackICE PC Protection, BlackICE Server Protection, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia-G 1.1 and earlier, Proventia Network IDS, Proventia Desktop, Proventia Server IPS for Linux technology, RealSecure Desktop Protector 3.6, Proventia Network IPS, Virtual Server Protection for Vmware:
This signature detects a user's attempt during an FTP session to use the MKD command referencing a directory name longer than the system-configurable maximum file name length.
High
RealSecure Server Sensor: 7.0, RealSecure Desktop Protector: 3.6, RealSecure Network: 7.0, BlackICE Agent for Server: 3.6, RealSecure Guard: 3.6, RealSecure Sentry: 3.6, BlackICE PC Protection: 3.6.cbd, BlackICE Server Protection: 3.6.cbd, Proventia Network MFS: 1.0, IBM Security Server Protection for Windows: 1.0.914.0, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia-G 1.1 and earlier: G Series, Proventia Network IDS: A Series, Proventia Desktop: 8.0.614.1, RealSecure Desktop: baseline, Proventia Server IPS for Linux technology: 1.0, RealSecure Desktop Protector 3.6: baseline, Proventia Network IPS: 2.0, Virtual Server Protection for Vmware: 1.0
Ipswitch WS_FTP Server: 2.0.2
Unauthorized Access Attempt
WS_FTP Server is vulnerable to a buffer overflow. By sending a command followed by a long character string, a remote attacker can overflow a buffer and execute arbitrary code on the system with system privileges.
The vulnerable commands are DELE, MDTM, MLST, MKD, RMD, RNFR, RNTO, SIZE, STAT, XMKD, and XRMD.
Upgrade to the latest version of WS_FTP Server (2.0.3 or later), available from the WS_FTP Server Support Center. See References.
Defcom Labs Advisory def-2001-28
WS_FTP server 2.0.2 Buffer Overflow and possible DOS
http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.html
WS_FTP Server Support Center
Patches & Upgrades
http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html
ISS X-Force
WS_FTP Server long command buffer overflow
http://www.iss.net/security_center/static/6911.php
CVE
CVE-2001-1021
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1021