gFTP Remote Format String Vulnerability
BID:2657
Info
gFTP Remote Format String Vulnerability
| Bugtraq ID: | 2657 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2001 12:00AM |
| Updated: | Apr 23 2001 12:00AM |
| Credit: | This vulnerability was discovered by SRTeam of www.snosoft.com and was published on April 17, 2001. |
| Vulnerable: |
Redhat gftp-2.0.7b-3.i386.rpm Redhat gftp-2.0.7b-2.i386.rpm Redhat gftp-2.0.6a-3.i386.rpm gFTP gFTP 2.0.7 gFTP gFTP 2.0.6 gFTP gFTP 2.0.5 gFTP gFTP 2.0.4 gFTP gFTP 2.0.3 gFTP gFTP 2.0.2 gFTP gFTP 2.0.1 gFTP gFTP 2.0 gFTP gFTP 1.13 gFTP gFTP 1.12 gFTP gFTP 1.11 gFTP gFTP 1.1 gFTP gFTP 1.0 gFTP gFTP 0.21 gFTP gFTP 0.2 gFTP gFTP 0.1 |
| Not Vulnerable: |
gFTP gFTP 2.0.8 |
Discussion
gFTP Remote Format String Vulnerability
gFTP is a freely available graphical file transfer client for UNIX based machines running X11R6 or later. It includes support for file transfers using the FTP, HTTP, and SSH protocols.
A format string bug exists in the facility used by the gftp client program to log FTP and HTTP responses. As a result, it may be possible for a malicious remote server to execute arbitrary code on a user's system.
gFTP is a freely available graphical file transfer client for UNIX based machines running X11R6 or later. It includes support for file transfers using the FTP, HTTP, and SSH protocols.
A format string bug exists in the facility used by the gftp client program to log FTP and HTTP responses. As a result, it may be possible for a malicious remote server to execute arbitrary code on a user's system.