J-Security Center

Title: ntop -i Local Format String Vulnerability

Severity: INFO

Description:

ntop (network top) is a unix program used for displaying network usage statistics. It is often installed setuid root because it uses privileged ports.

ntop is vulnerable to a format string vulnerability that can compromise root access locally. If present, the argument to the "-i" command-line option is passed directly to a *printf function without being checked. It is thus possible for an attacker insert format specifiers that will be interpreted by the *printf function. Malicious format specifiers can cause the function to overwrite memory locations on the program's stack with user supplied data. This can lead to execution of arbitrary code with the effective privileges of the process (if setuid root, superuser privs).

Affected Products:

  • Luca Deri ntop 1.1.0pre3
  • Luca Deri ntop 1.2.0a10
  • Luca Deri ntop 1.2.0a7-9
  • Luca Deri ntop 1.3.1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.