3Com 3CDaemon Buffer Overflow Vulnerability
BID:4638
Info
3Com 3CDaemon Buffer Overflow Vulnerability
| Bugtraq ID: | 4638 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0606 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by skyrim msh <[email protected]>. |
| Vulnerable: |
3Com 3CDaemon 2.0 revision 10 |
| Not Vulnerable: | |
Discussion
3Com 3CDaemon Buffer Overflow Vulnerability
3CDaemon is an FTP server developed by Dan Gill of 3Com.
Reportedly, it is possible to initiate a buffer overflow on a host running 3CDaemon.
Submitting an unusually large amount of data to the ftp server, could trigger a stack-based overflow condition. This could potentially allow for malicious users to execute arbitrary code on the server. However, sending random data could cause the application to crash.
3CDaemon is an FTP server developed by Dan Gill of 3Com.
Reportedly, it is possible to initiate a buffer overflow on a host running 3CDaemon.
Submitting an unusually large amount of data to the ftp server, could trigger a stack-based overflow condition. This could potentially allow for malicious users to execute arbitrary code on the server. However, sending random data could cause the application to crash.
Exploit / POC
3Com 3CDaemon Buffer Overflow Vulnerability
An Exploit has been provided by skyrim msh <[email protected]>.
Exploit code 3cdv2r10_bof.c has been provided by Hat-Squad Security Team.
An Exploit has been provided by skyrim msh <[email protected]>.
Exploit code 3cdv2r10_bof.c has been provided by Hat-Squad Security Team.