Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
BID:5427
Info
Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 5427 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2002 12:00AM |
| Updated: | Aug 08 2002 12:00AM |
| Credit: | Credited to Andreas Junestam ([email protected]). |
| Vulnerable: |
Ipswitch WS FTP Server 3.1.1 |
| Not Vulnerable: |
Ipswitch WS FTP Server 3.1.2 |
Discussion
Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
Ipswitch WS_FTP Server, is a FTP server for Microsoft Windows platforms.
Ipswitch WS FTP Server contains a remote buffer overflow vulnerability related to the CPWD command, used to modify an authenticated user's password. Oversized parameters may corrupt process memory, possibly leading to the execution of arbitrary code as the server process.
This issue has been reported in WS_FTP Server 3.1.1. Earlier versions may share this vulnerability, this has not however been confirmed.
Ipswitch WS_FTP Server, is a FTP server for Microsoft Windows platforms.
Ipswitch WS FTP Server contains a remote buffer overflow vulnerability related to the CPWD command, used to modify an authenticated user's password. Oversized parameters may corrupt process memory, possibly leading to the execution of arbitrary code as the server process.
This issue has been reported in WS_FTP Server 3.1.1. Earlier versions may share this vulnerability, this has not however been confirmed.
Solution / Fix
Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
Solution:
An update is available:
Ipswitch WS FTP Server 3.1.1
Solution:
An update is available:
Ipswitch WS FTP Server 3.1.1
-
Ipswitch ifs312.exe
ftp://ftp.ipswitch.com/ipswitch/product_support/WS_FTP_Server/ifs312.e xe