GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
BID:11776
Info
GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11776 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2004 12:00AM |
| Updated: | Nov 30 2004 12:00AM |
| Credit: | Hongzhen Zhou <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
globalSCAPE CuteFTP 6.0 |
| Not Vulnerable: | |
Discussion
GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.
A remote attacker may leverage these issues to cause the affected client to crash; code execution may also be possible. Any code execution would take place with the privileges of the user that activated the vulnerable application.
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.
A remote attacker may leverage these issues to cause the affected client to crash; code execution may also be possible. Any code execution would take place with the privileges of the user that activated the vulnerable application.
Exploit / POC
GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities
References:
References:
- CuteFTP Product Page (globalSCAPE)
- CuteFTP 6.0 Professional Remote Buffer Overflow Vulnerability (Hongzhen Zhou
)