Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

BID:5328

Info

Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

Bugtraq ID: 5328
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jul 27 2002 12:00AM
Updated: Jul 27 2002 12:00AM
Credit: Vulnerability discovery credited to FX <[email protected]>, FtR <[email protected]>, and kim0 <[email protected]>.
Vulnerable: Cisco MGX 8850 - PXM1 1.2.10
Cisco MGX 8850 - PXM1 1.2.10
Cisco MGX 8250 1.2.10
Cisco MGX 8250 1.2.10
Cisco MGX 8230 1.2.10
Cisco MGX 8230 1.2.10
Cisco IOS 11.3
Cisco IOS 11.2
Cisco IOS 11.1
Not Vulnerable: Cisco MGX 8850 - PXM1 1.2.11
Cisco MGX 8850
Cisco MGX 8830
Cisco MGX 8250 1.2.11
Cisco MGX 8230 1.2.11
Cisco IOS 12.1
Cisco IOS 12.0

Discussion

Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

A problem has been discovered in Cisco IOS and MGX switches that could result in a denial of service, and potential code execution.

It has been discovered that the TFTP server file name handling of Cisco IOS is vulnerable to a buffer overflow. This overflow results due insufficient bounds checking on requested file names. A request for a file name of 700 or more bytes will result a crash of the router, and reboot of the device.

On Cisco MGX switches, the TFTP service will fail but the device will continue to function.

Cisco IOS versions 12.0 and later are not prone to this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.

Cisco has announced that some MGX switches are also affected by this issue. Cisco has assigned Cisco Bug ID CSCdy03429 to this vulnerability.

Exploit / POC

Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

The following proof of concept has been made available by kim0 <[email protected]>.

tftp> get AAAAAAAAA....(700 times)

An exploit has been provided by FX <[email protected]>:

Solution / Fix

Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

Solution:
Cisco has announced that software upgrades will not be made available. The vendor has suggested the following workarounds in lieu of fixes:

Cisco has released MGX software 1.2.11 which addresses this issue. The fixes can be obtained if you have a service contract from the Software Center on Cisco's Worldwide Web site at http://www.cisco.com. Otherwise, further information on how to obtain this software can be obtained by contacting the vendor.

References

Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report