Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
BID:40309
Info
Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 40309 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2010 12:00AM |
| Updated: | May 21 2010 12:00AM |
| Credit: | sinn3r |
| Vulnerable: |
NetManage Rumba FTP 4.2 |
| Not Vulnerable: |
NetManage Rumba FTP 4.2.3 |
Discussion
Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
Rumba FTP client ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The issue affects Rumba FTP client version 4.2.0.0.
Rumba FTP client ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The issue affects Rumba FTP client version 4.2.0.0.
Exploit / POC
Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
Solution:
Reportedly, the vulnerability is fixed in version 4.2.3.0.0 but this has not been confirmed.
Solution:
Reportedly, the vulnerability is fixed in version 4.2.3.0.0 but this has not been confirmed.
References
Rumba FTP Client 'FTPSFtp.dll' ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Rumba FTP Client Homepage (NetManage)