Cerberus FTP Server Buffer Overflow DoS Vulnerability
BID:2901
Info
Cerberus FTP Server Buffer Overflow DoS Vulnerability
| Bugtraq ID: | 2901 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0702 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was discovered by Cartel Informatique Security Research Labs <[email protected]> and submitted to BugTraq on June 21st, 2001. |
| Vulnerable: |
Grant Averett Ceberus FTP Server 1.22 Grant Averett Ceberus FTP Server 1.5 Grant Averett Ceberus FTP Server 1.3 Grant Averett Ceberus FTP Server 1.2 Grant Averett Ceberus FTP Server 1.1 Grant Averett Ceberus FTP Server 1.0 1 Grant Averett Ceberus FTP Server 1.0 |
| Not Vulnerable: | |
Discussion
Cerberus FTP Server Buffer Overflow DoS Vulnerability
Cerberus FTP Server is a free, multi-threaded file transfer utility for Microsoft Windows systems.
There is a buffer overflow in Cerberus FTP Server. The problem occurs when a user is attempting to authenticate. If the login fields(username, password) are filled with an excessive amount of characters(300+) then the affected service will crash. The FTP Server software will need to be restarted to regain normal functionality.
It has also been reported that entering an excessive amount of characters in just the password field will acheive the same result.
Due to the fact that the problem stems from a buffer overflow, there is a possibility that arbitrary code may be executed on the vulnerable host.
This vulnerability does not require any user authentication to exploit. It may be possible for remote users to cause a denial of service or execute arbitrary code on target hosts.
Cerberus FTP Server is a free, multi-threaded file transfer utility for Microsoft Windows systems.
There is a buffer overflow in Cerberus FTP Server. The problem occurs when a user is attempting to authenticate. If the login fields(username, password) are filled with an excessive amount of characters(300+) then the affected service will crash. The FTP Server software will need to be restarted to regain normal functionality.
It has also been reported that entering an excessive amount of characters in just the password field will acheive the same result.
Due to the fact that the problem stems from a buffer overflow, there is a possibility that arbitrary code may be executed on the vulnerable host.
This vulnerability does not require any user authentication to exploit. It may be possible for remote users to cause a denial of service or execute arbitrary code on target hosts.
Solution / Fix
Cerberus FTP Server Buffer Overflow DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.