Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
BID:38321
Info
Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
| Bugtraq ID: | 38321 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2010 12:00AM |
| Updated: | Jul 28 2010 08:05PM |
| Credit: | ThE g0bL!N |
| Vulnerable: |
uplusware UplusFtp 1.7.1 .01 uplusware UplusFtp 1.7 .12 easy ftp server easy ftp server 1.7 2 |
| Not Vulnerable: |
uplusware UplusFtp 1.7.1 .02 |
Discussion
Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
Easy FTP Server (also known as UplusFTP) is prone to a buffer-overflow vulnerability.
Successful exploits may allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
Easy FTP Server 1.7.0.2, 1.7.0.12, and 1.7.1.01 are vulnerable; other versions may also be affected.
Easy FTP Server (also known as UplusFTP) is prone to a buffer-overflow vulnerability.
Successful exploits may allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
Easy FTP Server 1.7.0.2, 1.7.0.12, and 1.7.1.01 are vulnerable; other versions may also be affected.
Exploit / POC
Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
uplusware UplusFtp 1.7 .12
easy ftp server easy ftp server 1.7 2
uplusware UplusFtp 1.7.1 .01
Solution:
Updates are available. Please see the references for more information.
uplusware UplusFtp 1.7 .12
-
uplusware uplusftp-server-1.7.1.02-en.zip
http://easyftpsvr.googlecode.com/files/uplusftp-server-1.7.1.02-en.zip
easy ftp server easy ftp server 1.7 2
-
uplusware uplusftp-server-1.7.1.02-en.zip
http://easyftpsvr.googlecode.com/files/uplusftp-server-1.7.1.02-en.zip
uplusware UplusFtp 1.7.1 .01
-
uplusware uplusftp-server-1.7.1.02-en.zip
http://easyftpsvr.googlecode.com/files/uplusftp-server-1.7.1.02-en.zip
References
Easy FTP Server (AKA UplusFTP) 'Path' Parameter Buffer Overflow Vulnerability
References:
References:
- Easy FTP Server Project Page (SourceForge)
- UplusFtp Homepage (uplusware)