Pi-Soft SpoonFTP 'CWD' and 'LIST' Buffer Overflow Vulnerability
BID:2803
Info
Pi-Soft SpoonFTP 'CWD' and 'LIST' Buffer Overflow Vulnerability
| Bugtraq ID: | 2803 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2001 12:00AM |
| Updated: | May 30 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by SNS Research <[email protected]> on May 30, 2001. |
| Vulnerable: |
Pi-Soft SpoonFTP 1.0 0.12 Pi-Soft SpoonFTP 1.0 |
| Not Vulnerable: |
Pi-Soft SpoonFTP 1.0 0.13 |
Discussion
Pi-Soft SpoonFTP 'CWD' and 'LIST' Buffer Overflow Vulnerability
Invalid long strings submitted using either 'LIST' or 'CWD' commands to a host running SpoonFTP server, will result in the service terminating due to a buffer overflow. It is possible for an attacker to execute arbitrary code through this vulnerability.
A restart of the server is required in order to regain normal functionality.
Invalid long strings submitted using either 'LIST' or 'CWD' commands to a host running SpoonFTP server, will result in the service terminating due to a buffer overflow. It is possible for an attacker to execute arbitrary code through this vulnerability.
A restart of the server is required in order to regain normal functionality.
Solution / Fix
Pi-Soft SpoonFTP 'CWD' and 'LIST' Buffer Overflow Vulnerability
Solution:
Pi-Soft has addressed this issue in SpoonFTP 1.0.0.13. Contact the vendor for the latest version.
Solution:
Pi-Soft has addressed this issue in SpoonFTP 1.0.0.13. Contact the vendor for the latest version.
References
Pi-Soft SpoonFTP 'CWD' and 'LIST' Buffer Overflow Vulnerability
References:
References:
- Pi-Soft Homepage (Pi-Soft)