ToxSoft NextFTP Buffer Overflow Vulnerability
BID:572
Info
ToxSoft NextFTP Buffer Overflow Vulnerability
| Bugtraq ID: | 572 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 1999 12:00AM |
| Updated: | Aug 03 1999 12:00AM |
| Credit: | Posted to the Shadow Penguin Security website August 3, 1999 by UNYUN. |
| Vulnerable: |
ToxSoft NextFTP 1.82 |
| Not Vulnerable: | |
Discussion
ToxSoft NextFTP Buffer Overflow Vulnerability
ToxSoft's shareware FTP client, NextFTP, contains an unchecked buffer in the code that parses CWD command replies. If the FTP server's reply contains the exploit code, arbitrary commands can be run on the client machine.
ToxSoft's shareware FTP client, NextFTP, contains an unchecked buffer in the code that parses CWD command replies. If the FTP server's reply contains the exploit code, arbitrary commands can be run on the client machine.
Exploit / POC
Solution / Fix
ToxSoft NextFTP Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
ToxSoft NextFTP Buffer Overflow Vulnerability
References:
References:
- NextFTP Version 1.82 Overflow Exploit on Windows9/NT (Shadow Penguin Security)