LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
BID:14655
Info
LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14655 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2005 12:00AM |
| Updated: | Aug 24 2005 12:00AM |
| Credit: | Discovery is credited to Sowhat . <[email protected]>. |
| Vulnerable: |
LeapWare LeapFTP 2.7.4 .602 LeapWare LeapFTP 2.7.4 LeapWare LeapFTP 2.7.3 .600 |
| Not Vulnerable: |
LeapWare LeapFTP 2.7.6 .612 |
Discussion
LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
LeapFTP client is prone to a remote buffer overflow vulnerability.
The issue arises when the client handles a malformed LeapFTP Site Queue (.lsq) file.
A remote attacker may gain unauthorized access in the context of the user running the application.
LeapFTP versions prior to 2.7.6.612 are affected by this vulnerability.
LeapFTP client is prone to a remote buffer overflow vulnerability.
The issue arises when the client handles a malformed LeapFTP Site Queue (.lsq) file.
A remote attacker may gain unauthorized access in the context of the user running the application.
LeapFTP versions prior to 2.7.6.612 are affected by this vulnerability.
Exploit / POC
LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept is available:
//bof.lsq
[HOSTINFO]
HOST=AAAAA...[ long string ]...AAAAA
USER=username
PASS=password
[FILES]
"1","/winis/ApiList.zip","477,839","E:\ApiList.zip"
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept is available:
//bof.lsq
[HOSTINFO]
HOST=AAAAA...[ long string ]...AAAAA
USER=username
PASS=password
[FILES]
"1","/winis/ApiList.zip","477,839","E:\ApiList.zip"
Solution / Fix
LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
Solution:
The vendor has released LeapFTP 2.7.6.612 to address this issue.
LeapWare LeapFTP 2.7.3 .600
LeapWare LeapFTP 2.7.4 .602
LeapWare LeapFTP 2.7.4
Solution:
The vendor has released LeapFTP 2.7.6.612 to address this issue.
LeapWare LeapFTP 2.7.3 .600
-
LeapWare LeapFTP 2.7.6.612
http://www.leapware.com/download.html
LeapWare LeapFTP 2.7.4 .602
-
LeapWare LeapFTP 2.7.6.612
http://www.leapware.com/download.html
LeapWare LeapFTP 2.7.4
-
LeapWare LeapFTP 2.7.6.612
http://www.leapware.com/download.html
References
LeapFTP Client LSQ File Remote Buffer Overflow Vulnerability
References:
References:
- LeapFTP Homepage (LeapWare)
- LeapFTP .lsq Buffer Overflow Vulnerability ("Sowhat ."
)