Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Tftpd32 Request Error Message Format String Vulnerability

Subscribe

Check Point Reference: CPAI-2006-027
Date Published:
Severity:
Last Updated:
Source:

FrSIRT/ADV-2006-0263

Industry Reference(s): CVE-2006-0328
Protection Provided by: InterSpect
  • NGX
Who is Vulnerable?
Tftpd32 version 2.81 and earlier versions
Vulnerability Description
Tftpd32 is a freeware TFTP server designed for Microsoft Windows operating systems. A vulnerability has been identified in Tftpd32, specifically in the processing of Get requests containing a malformed filename. An attacker capable of sending a specially crafted filename can cause a vulnerable application to execute code or to crash.
Update/Patch Available
We are not aware of any official patch for this issue.
Vulnerability Details
The flaw is due to a format string error when processing a specially crafted GET request containing a malformed filename.

Protection Overview
The Update enables the HTTP Worm Catcher to detect and block the vulnerability based on pre-defined worm signatures. The update applies to users of InterSpect NGX only.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
The update also includes the following protections:

  • Enhancement to the Microsoft Windows Media Player Vulnerability (CPAI-2006-016)
  • Trojan Spy Goldun.de Protection (CPAI-2006-025)
  • ezDatabase Remote File Inclusion Protection (CPAI-2006-026)
  • Cisco IOS CDP Status Page Code Injection Protection (CPAI-2006-028)
  • SHOUTcast Filename Request Format String Protection (CPAI-2006-029)
  • Oracle Report File Overwrite/Oracle Report Directory Traversal Protection (CPAI-2006-030)
  • Google Talk via Gmail Web Interface Protection (CPSA-2006-02)
  • IBM Tivoli Access Manager Directory Traversal Protection (CPAI-2006-031)
  • Protection Against NFS Vulnerabilities (CPAI-2006-032)
  • Protection against PmWiki multiple vulnerabilities

InterSpect NGX

How Can I Protect My Network?
1. Update SmartDefense: In the left pane from the drop-down list, select Profiles > SmartDefense Service and click the Online Update button.
2. In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.
3. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
4. Enable the following pattern:

Tftpd32 Request Error Message Format String Vulnerability

5. Install policy on all modules. 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: Tftpd32 Request Error Message Format String Vulnerability