Pablo Software Solutions FTP Server Format String Vulnerability
BID:6099
Info
Pablo Software Solutions FTP Server Format String Vulnerability
| Bugtraq ID: | 6099 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1244 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Texonet (http://www.texonet.com). |
| Vulnerable: |
Pablo Software Solutions FTP Service 1.5 Pablo Software Solutions FTP Service 1.3 Pablo Software Solutions FTP Service 1.2 Pablo Software Solutions FTP Service 1.0 |
| Not Vulnerable: |
Pablo Software Solutions FTP Service 1.51 |
Discussion
Pablo Software Solutions FTP Server Format String Vulnerability
A format string vulnerability has been reported in Pablo Software Solutions FTP Server. The vulnerability occurs due to inadequate checking of user-supplied input for the login credentials.
An attacker can exploit this vulnerability by logging into the FTP server with a username that includes malicious format specifiers. This may result in memory being overwritten by remote attackers, possibly to execute arbitrary code.
Attacker-supplied code will be executed with the privileges of the FTP server.
A format string vulnerability has been reported in Pablo Software Solutions FTP Server. The vulnerability occurs due to inadequate checking of user-supplied input for the login credentials.
An attacker can exploit this vulnerability by logging into the FTP server with a username that includes malicious format specifiers. This may result in memory being overwritten by remote attackers, possibly to execute arbitrary code.
Attacker-supplied code will be executed with the privileges of the FTP server.
Solution / Fix
Pablo Software Solutions FTP Server Format String Vulnerability
Solution:
Pablo FTP Server 1.51 is not vulnerable to this issue. Users are advised to upgrade any vulnerable versions:
Pablo Software Solutions FTP Service 1.0
Pablo Software Solutions FTP Service 1.2
Pablo Software Solutions FTP Service 1.3
Pablo Software Solutions FTP Service 1.5
Solution:
Pablo FTP Server 1.51 is not vulnerable to this issue. Users are advised to upgrade any vulnerable versions:
Pablo Software Solutions FTP Service 1.0
-
Pablo Software Solutions ftpserver.zip
http://www.pablovandermeer.nl/ftpserver.zip
Pablo Software Solutions FTP Service 1.2
-
Pablo Software Solutions ftpserver.zip
http://www.pablovandermeer.nl/ftpserver.zip
Pablo Software Solutions FTP Service 1.3
-
Pablo Software Solutions ftpserver.zip
http://www.pablovandermeer.nl/ftpserver.zip
Pablo Software Solutions FTP Service 1.5
-
Pablo Software Solutions ftpserver.zip
http://www.pablovandermeer.nl/ftpserver.zip
References
Pablo Software Solutions FTP Server Format String Vulnerability
References:
References:
- FTP Service Homepage (Pablo Software Solutions)