TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
BID:55764
Info
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 55764 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2012 12:00AM |
| Updated: | Oct 22 2012 06:30AM |
| Credit: | Zhao Liang of Beijing Leadsec Technology |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
TurboFTP Server is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected server. Successful attacks will compromise the server and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
TurboFTP Server 1.30.823 is vulnerable; other versions may also be affected.
TurboFTP Server is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected server. Successful attacks will compromise the server and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
TurboFTP Server 1.30.823 is vulnerable; other versions may also be affected.
Exploit / POC
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
References:
References:
- TurboFTP Web Site (TurboFTP)