TransSoft Broker User Name Buffer Overflow Vulnerability
BID:783
Info
TransSoft Broker User Name Buffer Overflow Vulnerability
| Bugtraq ID: | 783 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 08 1999 12:00AM |
| Updated: | Nov 08 1999 12:00AM |
| Credit: | Posted to Bugtraq on November 8, 1999 by Ussr Labs <[email protected]>. |
| Vulnerable: |
TransSoft Broker FTP Server 4.0 TransSoft Broker FTP Server 3.0 x |
| Not Vulnerable: | |
Discussion
TransSoft Broker User Name Buffer Overflow Vulnerability
If an unusually long user name is passed to the Broker FTP server software, the program will crash. If the program is running as a service, the service will consume all available memory and crash the entire system.
If an unusually long user name is passed to the Broker FTP server software, the program will crash. If the program is running as a service, the service will consume all available memory and crash the entire system.
Exploit / POC
TransSoft Broker User Name Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
TransSoft Broker User Name Buffer Overflow Vulnerability
Solution:
This problem has been addressed in the latest version of TransSoft Broker:
TransSoft Broker FTP Server 3.0 x
TransSoft Broker FTP Server 4.0
Solution:
This problem has been addressed in the latest version of TransSoft Broker:
TransSoft Broker FTP Server 3.0 x
-
TransSoft broker40b
Windows 95/98
http://www.transsoft.com/broker/updates/broker40b.exe -
TransSoft broker40nt
Windows NT
http://www.transsoft.com/broker/updates/broker40nt.exe
TransSoft Broker FTP Server 4.0
-
TransSoft broker40b
Windows 95/98
http://www.transsoft.com/broker/updates/broker40b.exe -
TransSoft broker40nt
Windows NT
http://www.transsoft.com/broker/updates/broker40nt.exe
References
TransSoft Broker User Name Buffer Overflow Vulnerability
References:
References:
- Broker Homepage (TransSoft)
- Remote DoS Attack in TransSoft's Broker Ftp Server v3.5 Vulnerability (USSR Labs)