WVTFTP Server Remote Buffer Overflow Vulnerability
BID:11525
Info
WVTFTP Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11525 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Sean <[email protected]>. |
| Vulnerable: |
Net Integration Technologies Inc. WvTftp 0.9 |
| Not Vulnerable: | |
Discussion
WVTFTP Server Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects WvTftp. This issue is due to a failure of the application to properly to do proper sanity checking on string value pairs in TFTP packets.
An attacker may leverage this issue to corrupt process heap memory, facilitating code execution and a compromise of the affected computer. It is also reported that the affected TFTP server runs with superuser privileges by default.
A remote buffer overflow vulnerability affects WvTftp. This issue is due to a failure of the application to properly to do proper sanity checking on string value pairs in TFTP packets.
An attacker may leverage this issue to corrupt process heap memory, facilitating code execution and a compromise of the affected computer. It is also reported that the affected TFTP server runs with superuser privileges by default.
Exploit / POC
WVTFTP Server Remote Buffer Overflow Vulnerability
The following exploit has been provided:
The following exploit has been provided:
Solution / Fix
WVTFTP Server Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WVTFTP Server Remote Buffer Overflow Vulnerability
References:
References:
- Nitix Home Page (Net Integration Technologies Inc.)
- WvTftp Home Page (Net Integration Technologies Inc.)
- wvtfpd remote root heap overflow ([email protected])