Groups | Blog | Home
all groups > iis ftp > july 2004 >

iis ftp : getcwd() file descriptor leak in FTP


killy
7/26/2004 12:07:49 PM
hi everybody

I have an IIS FTP server running on windows server. I have the following
sec. problem:

#######################################
Name: CVE-1999-0083
Reference: XF:cwdleak

getcwd() file descriptor leak in FTP
#######################################

What can I do with this vulnerability problem?Thanks !

killy
7/26/2004 12:49:55 PM
hi

yes is an iis ftp !

ciao sven

[quoted text, click to view]
Paul Lynch
7/26/2004 1:38:34 PM
On Mon, 26 Jul 2004 12:07:49 +0200, killy <sven.killy@siemens.com>
[quoted text, click to view]

Why do you think this is a problem that affects IIS ? And which
version of IIS are you talking about ?

What evidence do you have to suggest that this problem affects any
version of IIS FTP services ?

As far as I can tell it only affects Unix systems :

http://xforce.iss.net/xforce/xfdb/335

If you have any information and/or supporting evidence which
contradicts this, or if you claim to be able to prove that this
problem affects IIS then please post your findings here.


Regards,

Paul Lynch
killy
7/26/2004 4:00:39 PM
hi paul

thanks alot !!

i wasn't shure that the problem depents on the ftp server

ciao sven

[quoted text, click to view]
Paul Lynch
7/26/2004 5:42:23 PM
On Mon, 26 Jul 2004 16:00:39 +0200, killy <sven.killy@siemens.com>
[quoted text, click to view]

I don't get it. Are you affected by this problem or not ? If so how ?


Regards,

Paul Lynch
Bernard
7/26/2004 6:30:36 PM
On IIS ? do you have other ftp server running?
I don't think this belong to IIS FTP.


--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

Bernard
7/27/2004 1:46:24 PM
As me and Paul pointed out, this is not belong to IIS FTP.
what other ftp software you running ?

--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

AddThis Social Bookmark Button