Xftp 'LIST' Response Remote Buffer Overflow Vulnerability
BID:40470
Info
Xftp 'LIST' Response Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 40470 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2010 12:00AM |
| Updated: | Jun 01 2010 12:00AM |
| Credit: | sinn3r |
| Vulnerable: |
NetSarang Xftp 3.0 Build 239 |
| Not Vulnerable: |
NetSarang Xftp 3.0 Build 243 |
Discussion
Xftp 'LIST' Response Remote Buffer Overflow Vulnerability
Xftp is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Xftp 3.0 Build 239 is vulnerable; other versions may also be affected.
Xftp is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Xftp 3.0 Build 239 is vulnerable; other versions may also be affected.
Exploit / POC
Xftp 'LIST' Response Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Xftp 'LIST' Response Remote Buffer Overflow Vulnerability
Solution:
Reportedly the vendor has fixed the issue in version 3.0 Build 243, however Symantec has not confirmed this. Please contact the vendor for more details.
Solution:
Reportedly the vendor has fixed the issue in version 3.0 Build 243, however Symantec has not confirmed this. Please contact the vendor for more details.