TransSoft Broker CWD Buffer Overflow Vulnerability
BID:2851
Info
TransSoft Broker CWD Buffer Overflow Vulnerability
| Bugtraq ID: | 2851 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0688 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported to bugtraq by ByteRage <[email protected]> on June 10, 2001. |
| Vulnerable: |
TransSoft Broker FTP Server 5.9.5 .0 TransSoft Broker FTP Server 5.7 TransSoft Broker FTP Server 5.1 TransSoft Broker FTP Server 5.0 TransSoft Broker FTP Server 4.7 .5.0 TransSoft Broker FTP Server 4.0 TransSoft Broker FTP Server 3.0 Build 1 |
| Not Vulnerable: | |
Discussion
TransSoft Broker CWD Buffer Overflow Vulnerability
Broker is a Windows FTP server from TransSoft.
Versions of Broker are vulnerable to a denial of service.
A CD or CWD command, argumented by an invalid '. .' (dot-space-dot) sequence can, if repeatedly issued, create a buffer overflow causing the server to halt, requiring a restart.
The extent of this issue's exploitability is currently unverified.
Broker is a Windows FTP server from TransSoft.
Versions of Broker are vulnerable to a denial of service.
A CD or CWD command, argumented by an invalid '. .' (dot-space-dot) sequence can, if repeatedly issued, create a buffer overflow causing the server to halt, requiring a restart.
The extent of this issue's exploitability is currently unverified.
Solution / Fix
TransSoft Broker CWD Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.