SmartFTP File List Command Buffer Overflow Vulnerability
BID:7861
Info
SmartFTP File List Command Buffer Overflow Vulnerability
| Bugtraq ID: | 7861 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2003 12:00AM |
| Updated: | Jun 09 2003 12:00AM |
| Credit: | Discovery is credited to nesumin <[email protected]>. |
| Vulnerable: |
SmartFTP SmartFTP 1.0.973 |
| Not Vulnerable: |
SmartFTP SmartFTP 1.0.976 |
Discussion
SmartFTP File List Command Buffer Overflow Vulnerability
SmartFTP is reportedly prone to a buffer overflow. If a File List command is issued to an FTP server, an overly long response could result in a boundary condition error. Arbitrary code execution is reportedly possible.
This issue was reported for SmartFTP 1.0.973, however, other versions may also be vulnerable.
SmartFTP is reportedly prone to a buffer overflow. If a File List command is issued to an FTP server, an overly long response could result in a boundary condition error. Arbitrary code execution is reportedly possible.
This issue was reported for SmartFTP 1.0.973, however, other versions may also be vulnerable.
Exploit / POC
SmartFTP File List Command Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SmartFTP File List Command Buffer Overflow Vulnerability
Solution:
This issue was reportedly corrected in SmartFTP 1.0.976, however, this has not been confirmed by Symantec.
SmartFTP SmartFTP 1.0.973
Solution:
This issue was reportedly corrected in SmartFTP 1.0.976, however, this has not been confirmed by Symantec.
SmartFTP SmartFTP 1.0.973
-
SmartFTP SmartFTP 1.0.976
http://www.smartftp.com/download/