LeapFTP Client PASV Response Buffer Overflow Vulnerability
BID:7860
Info
LeapFTP Client PASV Response Buffer Overflow Vulnerability
| Bugtraq ID: | 7860 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2003 12:00AM |
| Updated: | Jun 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Nesumin. |
| Vulnerable: |
LeapWare LeapFTP 2.7.3 .600 |
| Not Vulnerable: |
LeapWare LeapFTP 2.7.4 .602 |
Discussion
LeapFTP Client PASV Response Buffer Overflow Vulnerability
LeapFTP client has been reported prone to a remote buffer overflow vulnerability.
The issue is likely due to insufficient bounds checking and presents itself when the affected FTP client makes a connection to a malicious server that is running PASV mode. It has been reported that it is possible to supply and execute arbitrary code in the context of the user running LeapFTP client.
LeapFTP client has been reported prone to a remote buffer overflow vulnerability.
The issue is likely due to insufficient bounds checking and presents itself when the affected FTP client makes a connection to a malicious server that is running PASV mode. It has been reported that it is possible to supply and execute arbitrary code in the context of the user running LeapFTP client.
Exploit / POC
LeapFTP Client PASV Response Buffer Overflow Vulnerability
The following exploit was submitted by "drG4njubas" <[email protected]>:
The following exploit was submitted by "drG4njubas" <[email protected]>:
Solution / Fix
LeapFTP Client PASV Response Buffer Overflow Vulnerability
Solution:
The vendor has released an update to address this issue:
LeapWare LeapFTP 2.7.3 .600
Solution:
The vendor has released an update to address this issue:
LeapWare LeapFTP 2.7.3 .600
-
LeapWare LeapFTP_2.7.4.602
http://www.leapware.com/download.html
References
LeapFTP Client PASV Response Buffer Overflow Vulnerability
References:
References:
- LeapFTP Homepage (LeapWare)
- [LeapFTP] "PASV" Reply Buffer Overflow Vulnerability (":: Operash ::"
) - LeapFTP remote buffer overflow exploit ("drG4njubas"
)