3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
BID:11944
Info
3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11944 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Wang Ning <[email protected]>. |
| Vulnerable: |
3Com 3CDaemon 2.0 revision 10 |
| Not Vulnerable: | |
Discussion
3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
3CDaemon TFTP service is reported to be prone to a remote denial of service vulnerability. The vulnerability presents itself when any command is invoked that contains a superfluous filename parameter. When such a command is handled, the 3CDaemon will fail reporting opmode 0x01.
3CDaemon TFTP service is reported to be prone to a remote denial of service vulnerability. The vulnerability presents itself when any command is invoked that contains a superfluous filename parameter. When such a command is handled, the 3CDaemon will fail reporting opmode 0x01.
Exploit / POC
3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerability
References:
References:
- 3Com Homepage (3Com)
- 3cdaemon tftp server DOS vulnerability (Wang Ning
)