Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
BID:13790
Info
Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
| Bugtraq ID: | 13790 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1815 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery of this issue is credited to Ollie Whitehouse of Symantec. |
| Vulnerable: |
Hummingbird Connectivity 10.0 Hummingbird Connectivity 9.0 Hummingbird Connectivity 7.1 |
| Not Vulnerable: | |
Discussion
Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
Hummingbird Connectivity 10 FTP daemon is prone to a remote heap-based buffer overflow vulnerability. The issue manifests due to a lack of sufficient boundary checks performed on user-supplied data.
With successful exploitation, an unauthenticated attacker is able to leverage this issue to leak portions of memory from the vulnerable process.
Hummingbird Connectivity 10 FTP daemon is prone to a remote heap-based buffer overflow vulnerability. The issue manifests due to a lack of sufficient boundary checks performed on user-supplied data.
With successful exploitation, an unauthenticated attacker is able to leverage this issue to leak portions of memory from the vulnerable process.
Exploit / POC
Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.
Hummingbird Connectivity 10.0
Hummingbird Connectivity 9.0
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.
Hummingbird Connectivity 10.0
-
Hummingbird ftpdw_win32_1001.zip
Windows XP, Windows 2000, Windows 2003, Windows NT
http://support.hummingbird.com/customer/download.asp?r2=/exceed/10/ftp dw_win32_1001.zip -
Hummingbird ftpdw_win9x_1001.zip
Windows 98
http://support.hummingbird.com/customer/download.asp?r2=/exceed/10/ftp dw_win9x_1001.zip
Hummingbird Connectivity 9.0
-
Hummingbird ftpdw_win32_9004.zip
Windows XP, Windows 2000, Windows 2003, Windows NT
http://support.hummingbird.com/customer/download.asp?r2=/exceed/900/ft pdw_win32_9004.zip -
Hummingbird ftpdw_win9x_9004.zip
Windows 98
http://support.hummingbird.com/customer/download.asp?r2=/exceed/900/ft pdw_win9x_9004.zip
References
Hummingbird Connectivity 10 FTP Daemon Heap Overflow Vulnerability
References:
References:
- Connectivity Home Page (Hummingbird LTD.)
- FTPD Security Advisory Patch (Hummingbird LTD.)