Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
BID:19153
CVE-2006-3768 |Info
Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19153 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3768 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2006 12:00AM |
| Updated: | Jul 27 2006 06:07PM |
| Credit: | Carsten Eiram from Secunia Research is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Intervations FileCopa FTP Server 1.01.-2006-02-19 Intervations FileCopa FTP Server 1.01.-2005-11-21 Intervations FileCopa FTP Server 1.01 (2006-07-18) Intervations FileCopa FTP Server 1.01 (2006-04-06) Intervations FileCopa FTP Server 1.01 |
| Not Vulnerable: |
Intervations FileCopa FTP Server 1.01 -2006-07-21 |
Discussion
Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
FileCopa is prone to multiple buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
Successful exploits may allow remote attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.
FileCOPA 1.01 version 2006-07-18 is vulnerable; other versions may also be affected.
FileCopa is prone to multiple buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
Successful exploits may allow remote attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.
FileCOPA 1.01 version 2006-07-18 is vulnerable; other versions may also be affected.
Exploit / POC
Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
Attackers may exploit these issues with an FTP client.
Attackers may exploit these issues with an FTP client.
Solution / Fix
Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
Solution:
The vendor released version 1.01- 2006-07-21 to address these issues. Please see the references for more information.
Solution:
The vendor released version 1.01- 2006-07-21 to address these issues. Please see the references for more information.
References
Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
References:
References:
- FileCopa Homepage (Intervations)
- Secunia Research: FileCOPA Directory Argument Handling Buffer Overflow (Secunia Research)