Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
BID:19067
CVE-2006-3844 |Info
Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
| Bugtraq ID: | 19067 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3844 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2006 12:00AM |
| Updated: | Jun 03 2010 04:50PM |
| Credit: | h07 is credited with the discovery of this vulnerability. |
| Vulnerable: |
Pablo Software Solutions Quick And Easy FTP Server 3.0.2 Pablo Software Solutions Quick And Easy FTP Server 3.3 |
| Not Vulnerable: | |
Discussion
Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
Quick 'n Easy FTP Server is prone to a buffer-overflow vulnerability because it fails to do proper bounds checking on user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected server application, likely with SYSTEM-level privileges.
Quick 'n Easy FTP Server is prone to a buffer-overflow vulnerability because it fails to do proper bounds checking on user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected server application, likely with SYSTEM-level privileges.
Exploit / POC
Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
Exploit code has been provided:
Exploit code has been provided:
Solution / Fix
Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
References:
References:
- Quick 'n Easy FTP Server Homepage (Pablo Software Solutions)