WFTPD Server Multiple Buffer Overflow Vulnerabilities
BID:19617
CVE-2006-4318 |Info
WFTPD Server Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19617 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4318 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2006 12:00AM |
| Updated: | Dec 31 2008 03:11PM |
| Credit: | h07 <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Texas Imperial Software WFTPD 3.23 |
| Not Vulnerable: | |
Discussion
WFTPD Server Multiple Buffer Overflow Vulnerabilities
WFTPD is prone to multiple buffer-overflow vulnerabilities because the application fails to do proper bounds checking on user-supplied data before storing it in finite-sized buffers.
An attacker can exploit these issues to execute arbitrary code and gain unauthorized remote access to a computer. Attack attempts may cause denial-of-service conditions as well.
WFTPD 3.23 is reported vulnerable; other versions may also be affected.
WFTPD is prone to multiple buffer-overflow vulnerabilities because the application fails to do proper bounds checking on user-supplied data before storing it in finite-sized buffers.
An attacker can exploit these issues to execute arbitrary code and gain unauthorized remote access to a computer. Attack attempts may cause denial-of-service conditions as well.
WFTPD 3.23 is reported vulnerable; other versions may also be affected.
Exploit / POC
WFTPD Server Multiple Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
WFTPD Server Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WFTPD Server Multiple Buffer Overflow Vulnerabilities
References:
References:
- WFTPD Homepage (Texas Imperial Software)