FTP Voyager Remote LIST Buffer Overrun Vulnerability
BID:7862
Info
FTP Voyager Remote LIST Buffer Overrun Vulnerability
| Bugtraq ID: | 7862 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2003 12:00AM |
| Updated: | Jun 09 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to ":: Operash ::" <[email protected]>. |
| Vulnerable: |
RhinoSoft FtpTree Rhino Software FTP Voyager 10.0 .0.0 |
| Not Vulnerable: |
Rhino Software FTP Voyager 10.0 .0.1 |
Discussion
FTP Voyager Remote LIST Buffer Overrun Vulnerability
A buffer overrun vulnerability has been discovered in FTP Voyager. The problem is said to occur due to insufficient bounds checking and can be triggered by a malicious server. The overrun occurs while processing data returned by a server after the client makes a LIST request. This could ultimately result in the corruption of process memory and thus the execution of arbitrary code with the privileges of the user invoking the client.
A buffer overrun vulnerability has been discovered in FTP Voyager. The problem is said to occur due to insufficient bounds checking and can be triggered by a malicious server. The overrun occurs while processing data returned by a server after the client makes a LIST request. This could ultimately result in the corruption of process memory and thus the execution of arbitrary code with the privileges of the user invoking the client.
Exploit / POC
FTP Voyager Remote LIST Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FTP Voyager Remote LIST Buffer Overrun Vulnerability
Solution:
The vendor has released FTP Voyager 10.0.0.1 to address this issue. Users are advised to upgrade as soon as possible.
RhinoSoft FtpTree
Rhino Software FTP Voyager 10.0 .0.0
Solution:
The vendor has released FTP Voyager 10.0.0.1 to address this issue. Users are advised to upgrade as soon as possible.
RhinoSoft FtpTree
-
RhinoSoft FTP Voyager 10.0.0.1
http://www.ftpvoyager.com/
Rhino Software FTP Voyager 10.0 .0.0
-
RhinoSoft FTP Voyager 10.0.0.1
http://www.ftpvoyager.com/
References
FTP Voyager Remote LIST Buffer Overrun Vulnerability
References:
References:
- FTP Voyager 10.0.0.1 Release Notes (RhinoSoft)
- FTP Voyager Product Page (RhinoSoft)
- [FTP Voyager] File List Buffer Overflow Vulnerability (":: Operash ::"
)