Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
BID:31814
Info
Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
| Bugtraq ID: | 31814 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4652 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | InTeL |
| Vulnerable: |
Dart PowerTCP FTP for ActiveX 2.0.2 .0 |
| Not Vulnerable: | |
Discussion
Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
PowerTCP FTP for ActiveX is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
The issue affects PowerTCP FTP for ActiveX 2.0.2.0; other versions may also be affected.
PowerTCP FTP for ActiveX is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
The issue affects PowerTCP FTP for ActiveX 2.0.2.0; other versions may also be affected.
Exploit / POC
Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploits are available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploits are available:
Solution / Fix
Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Dart Communications PowerTCP FTP for ActiveX 'DartFtp.dll' Control Buffer Overflow Vulnerability
References:
References:
- Dart Communication Homepage (Dart Communication )
- FTP for ActiveX Homepage (Dart Communication)