DataWizard FtpXQ Buffer Overflow Vulnerability
BID:4862
Info
DataWizard FtpXQ Buffer Overflow Vulnerability
| Bugtraq ID: | 4862 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | May 27 2002 12:00AM |
| Credit: | Discovery credited to "SnakeByte / Eric Sesterhenn" <[email protected]>. |
| Vulnerable: |
DataWizard FtpXQ 2.5 |
| Not Vulnerable: | |
Discussion
DataWizard FtpXQ Buffer Overflow Vulnerability
FtpXQ is vulnerable to a buffer overflow which may result in a denial of service condition. Creating an exceptionally long directory name will cause the server to crash. It is also believed that attackers can cause arbirtary code to be executed on target servers, however this is not confirmed.
FtpXQ is vulnerable to a buffer overflow which may result in a denial of service condition. Creating an exceptionally long directory name will cause the server to crash. It is also believed that attackers can cause arbirtary code to be executed on target servers, however this is not confirmed.
Exploit / POC
DataWizard FtpXQ Buffer Overflow Vulnerability
There is no exploit required for this vulnerability.
There is no exploit required for this vulnerability.
Solution / Fix
DataWizard FtpXQ Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.