3Com SuperStack 3 NBX FTPD远程拒绝服务攻击漏洞

3Com SuperStack 3 NBX FTPD远程拒绝服务攻击漏洞

漏洞ID 1107121 漏洞类型 缓冲区溢出
发布时间 2002-12-02 更新时间 2002-12-31
图片[1]-3Com SuperStack 3 NBX FTPD远程拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2002-2300
图片[2]-3Com SuperStack 3 NBX FTPD远程拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200212-608
漏洞平台 Hardware CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/22060
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-608
|漏洞详情
3ComSuperstack3NBXIP电话系统使用嵌入式实时操作系统(EROTS),其中包含FTPD守护程序。EROTS操作系统的FTPD程序对超长CEL参数缺少正确处理,远程攻击者可以利用这个漏洞对IP电话系统进行拒绝服务攻击。攻击者可以向远程EROTS操作系统的FTPD程序发送参数超过2048字节长的CEL命令,可导致FTP服务程序崩溃,而且各种VoIP服务如基于WEB管理控制台、控制系统、进出电话都停止响应。目前未知是否可以利用这个漏洞执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/6297/info

It has been reported that the ftpd server, included in the Embedded Real Time Operating System (ERTOS) of 3Com Superstack 3 NBX IP phones, contains a denial of service vulnerability. This issue can be triggered by sending a CEL paramater of excessive length, effectively causing the ftpd server and various VoIP services to no longer respond.

It should be noted that this issue may be similar to the vulnerability described in BID 679.

Although unconfirmed, it should also be noted that due to the nature of this vulnerability under some circumstances it may be exploited to execute arbitrary code.

CEL aaaa[...]aaaa where string is 2048 bytes long
|参考资料

来源:XF
名称:3com-nbx-cel-bo(10739)
链接:http://xforce.iss.net/xforce/xfdb/10739
来源:BID
名称:6297
链接:http://www.securityfocus.com/bid/6297
来源:www.secnap.com
链接:http://www.secnap.com/alerts.php?pg=6
来源:SECTRACK
名称:1005732
链接:http://securitytracker.com/id?1005732
来源:BUGTRAQ
名称:200304273comNBXIPPhoneCallmanagerDenialofService-Update
链接:http://seclists.org/lists/bugtraq/2003/Apr/0344.html
来源:BUGTRAQ
名称:20021202[VU#317417]DenialofServiceconditioninvxworksftpd/3comnbx
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=103886644126011&w;=2
来源:NSFOCUS
名称:3962
链接:http://www.nsfocus.net/vulndb/3962

相关推荐: BeOS IP Packet Length Field Vulnerability

BeOS IP Packet Length Field Vulnerability 漏洞ID 1104252 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2000-04-07 更新时间 2000-04-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享