SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
BID:40265
Info
SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 40265 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2010 12:00AM |
| Updated: | Jan 13 2010 12:00AM |
| Credit: | Julien Bedard |
| Vulnerable: |
Dave Revell swiFTP 1.11 |
| Not Vulnerable: |
Dave Revell swiFTP 1.13 |
Discussion
SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
SwiFTP is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
SwiFTP 1.11 is vulnerable; other versions may also be affected.
SwiFTP is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
SwiFTP 1.11 is vulnerable; other versions may also be affected.
Exploit / POC
SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Dave Revell swiFTP 1.11
Solution:
Updates are available. Please see the references for details.
Dave Revell swiFTP 1.11
-
Dave Revell SwiFTP_1.13.apk
http://code.google.com/p/swiftp/downloads/detail?name=SwiFTP_1.13.apk& can=1&q=1.13
References
SwiFTP 'STOR' Command Remote Buffer Overflow Vulnerability
References:
References:
- SwiFTP Homepage (Dave Revell)