TFTP Server Packet Handling Remote Buffer Overflow Vulnerability
BID:28462
Info
TFTP Server Packet Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 28462 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1611 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2008 12:00AM |
| Updated: | May 07 2015 05:31PM |
| Credit: | Mati Aharoni |
| Vulnerable: |
TFTP Server TFTP Server 1.4 |
| Not Vulnerable: | |
Discussion
TFTP Server Packet Handling Remote Buffer Overflow Vulnerability
TFTP Server is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
TFTP Server 1.4 running on Windows is vulnerable; other versions may also be affected.
TFTP Server is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
TFTP Server 1.4 running on Windows is vulnerable; other versions may also be affected.
Exploit / POC
TFTP Server Packet Handling Remote Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
References
TFTP Server Packet Handling Remote Buffer Overflow Vulnerability
References:
References:
- Vendor Homepage (TFTP Server)