ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
BID:20131
CVE-2006-4948 |Info
ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 20131 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4948 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2006 12:00AM |
| Updated: | Aug 21 2009 03:58PM |
| Credit: | Discovery of this issue is credited to Parvez Anwar. |
| Vulnerable: |
ProSysInfo TFTPDWIN 0.4.2 |
| Not Vulnerable: | |
Discussion
ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
TFTPDWIN server is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code in the context of the TFTP server process.
TFTPDWIN 0.4.2 is vulnerable; other versions may be affected as well.
TFTPDWIN server is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code in the context of the TFTP server process.
TFTPDWIN 0.4.2 is vulnerable; other versions may be affected as well.
Exploit / POC
ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concepts and exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concepts and exploits are available:
Solution / Fix
ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ProSysInfo TFTPDWIN Remote Buffer Overflow Vulnerability
References:
References:
- ProSysInfo Home Page (ProSysInfo)