FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
BID:15346
Info
FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
| Bugtraq ID: | 15346 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2005 12:00AM |
| Updated: | Nov 07 2005 12:00AM |
| Credit: | [email protected] disclosed this issue. |
| Vulnerable: |
FileZilla FileZilla Server 0.9.4d |
| Not Vulnerable: | |
Discussion
FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
A remote, client-side buffer overflow vulnerability reportedly affects FileZilla Server Terminal. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote, client-side buffer overflow vulnerability reportedly affects FileZilla Server Terminal. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
The reporter of this issue has created a proof of concept denial of service exploit for this issue (FileZillaDoS.cpp):
The reporter of this issue has created a proof of concept denial of service exploit for this issue (FileZillaDoS.cpp):
Solution / Fix
FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FileZilla Server Terminal Remote Client-Side Buffer Overflow Vulnerability
References:
References: