Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
BID:20076
CVE-2006-4847 |Info
Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
| Bugtraq ID: | 20076 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4847 CVE-2006-5000 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | This vulnerability was discovered by an anonymous researcher. |
| Vulnerable: |
Ipswitch WS FTP Server 5.05 Ipswitch WS FTP Server 5.04 |
| Not Vulnerable: |
Ipswitch WS FTP Server 5.05 Hotfix 1 |
Discussion
Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
Ipswitch WS_FTP Server is prone to a number of stack-overflow vulnerabilities. Updates are available.
A successful exploit may lead to remote arbitrary code execution with administrative privileges, facilitating the complete compromise of affected computers.
Ipswitch WS_FTP Server 5.04 and 5.05 are vulnerable to these issues; other versions may also be affected.
Ipswitch WS_FTP Server is prone to a number of stack-overflow vulnerabilities. Updates are available.
A successful exploit may lead to remote arbitrary code execution with administrative privileges, facilitating the complete compromise of affected computers.
Ipswitch WS_FTP Server 5.04 and 5.05 are vulnerable to these issues; other versions may also be affected.
Exploit / POC
Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
Solution:
The vendor has released a hotfix to address these issues. Please see the vendor reference for more information.
Ipswitch WS FTP Server 5.05
Solution:
The vendor has released a hotfix to address these issues. Please see the vendor reference for more information.
Ipswitch WS FTP Server 5.05
-
Ipswitch WS_FTP Server 5.05 Hotfix 1
ftp://ftp.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs505hf 1.exe
References
Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
References:
References: