Search:     Advanced search
server monitoring

Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495)

Article ID: 19997
Last updated: 27 Jan, 2009
Views: 437
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495)

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyWindows : Microsoft Bulletins
Plugin ID19997
Bugtraq ID
CVE IDCVE-2005-2126

Description:

Synopsis :

A flaw in the FTP client installed on the remote host may allow a rogue
FTP server to write to arbitrary locations on the remote host.

Description :

The remote host contains a version of the Microsoft FTP client which contains
a flaw in the way it handles FTP download. An attacker may exploit this flaw
to modify the destination location for files downloaded via FTP.

To exploit this flaw an attacker would need to set up a rogue FTP server
and have a victim on the remote host connect to it and download a file
manaully.



Solution :

Microsoft has released a set of patches for Windows 2000, XP and 2003 :

http://www.microsoft.com/technet/security/bulletin/ms05-044.mspx

Risk factor :

Low / CVSS Base Score : 2.6
(CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
Vulnerability in Web View Could Allow Code Execution (894320)     Vulnerability in Outlook could allow code execution (828040)