WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
BID:15682
Info
WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 15682 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2005 12:00AM |
| Updated: | Dec 02 2005 12:00AM |
| Credit: | Discovered by Sowhat <[email protected]>. |
| Vulnerable: |
WinEggDropShell WinEggDropShell 1.7 |
| Not Vulnerable: | |
Discussion
WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
WinEggDropShell is affected by multiple remote buffer overflow vulnerabilities.
A remote buffer overflow vulnerability affecting the HTTP server arises when a GET request is provided with excessive data.
Two remote buffer overflow vulnerabilities affecting the FTP server arise when the FTP commands are provided with excessively long arguments.
An unauthenticated attacker may leverage these issues to execute arbitrary code on a computer with the privileges of the server process. This may facilitate unauthorized access and a complete compromise.
WinEggDropShell 1.7 is reportedly vulnerable, however, other versions are likely affected as well.
WinEggDropShell is affected by multiple remote buffer overflow vulnerabilities.
A remote buffer overflow vulnerability affecting the HTTP server arises when a GET request is provided with excessive data.
Two remote buffer overflow vulnerabilities affecting the FTP server arise when the FTP commands are provided with excessively long arguments.
An unauthenticated attacker may leverage these issues to execute arbitrary code on a computer with the privileges of the server process. This may facilitate unauthorized access and a complete compromise.
WinEggDropShell 1.7 is reportedly vulnerable, however, other versions are likely affected as well.
Exploit / POC
WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept is available:
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept is available:
Solution / Fix
WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WinEggDropShell Multiple Remote Buffer Overflow Vulnerabilities
References:
References: