BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
BID:33024
Info
BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 33024 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2008 12:00AM |
| Updated: | Apr 15 2009 06:06PM |
| Credit: | Stack |
| Vulnerable: |
BulletProof FTP BulletProof FTP 0 |
| Not Vulnerable: | |
Discussion
BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
BulletProof FTP Client is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker may exploit this issue to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in a denial-of-service condition.
BulletProof FTP Client is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker may exploit this issue to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in a denial-of-service condition.
Exploit / POC
BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit code are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit code are available:
Solution / Fix
BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BulletProof FTP Client '.bps' File Stack Buffer Overflow Vulnerability
References:
References:
- BulletProof FTP Client Homepage (BulletProof Software)