WinAgents TFTP Server Remote Buffer Overrun Vulnerability
BID:10526
Info
WinAgents TFTP Server Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 10526 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2004 12:00AM |
| Updated: | Jun 11 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Ziv Kamir, additional analysis performed by Claudiu Dragalina-Paraipan <[email protected]>. |
| Vulnerable: |
WinAgents TFTP Server 3.0 |
| Not Vulnerable: | |
Discussion
WinAgents TFTP Server Remote Buffer Overrun Vulnerability
WinAgents TFTP Server is reported prone to a remote off-by-one buffer overrun vulnerability. The issue is reported to exist due to a lack of sufficient boundary checks performed on filenames when a request is made for a file. A remote attacker may make a malicious request to the server for a filename of excessive length. This request will trigger the vulnerability. Immediate consequences of such an attack will reportedly result in a denial of service.
WinAgents TFTP Server is reported prone to a remote off-by-one buffer overrun vulnerability. The issue is reported to exist due to a lack of sufficient boundary checks performed on filenames when a request is made for a file. A remote attacker may make a malicious request to the server for a filename of excessive length. This request will trigger the vulnerability. Immediate consequences of such an attack will reportedly result in a denial of service.
Exploit / POC
WinAgents TFTP Server Remote Buffer Overrun Vulnerability
The following proof of concept example is available:
The following proof of concept example is available:
Solution / Fix
WinAgents TFTP Server Remote Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WinAgents TFTP Server Remote Buffer Overrun Vulnerability
References:
References:
- Short Analysis of WinAgents TFTP Server Remote DoS Attack (Claudiu Dragalina-Paraipan
) - TFTP Server for Windows (WinAgent)