IglooFTP PRO Multiple Buffer Overflow Vulnerabilities
BID:8117
Info
IglooFTP PRO Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 8117 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2003 12:00AM |
| Updated: | Jul 07 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Peter Winter-Smith <[email protected]>. |
| Vulnerable: |
IglooFTP IglooFTP PRO 3.8 |
| Not Vulnerable: |
IglooFTP IglooFTP PRO 3.9 |
Discussion
IglooFTP PRO Multiple Buffer Overflow Vulnerabilities
IglooFTP PRO for Windows platforms has been reported prone to multiple buffer overrun vulnerabilities.
The issue likely presents itself due do a lack of sufficient bounds checking performed on data that is copied into a reserved internal memory buffer. Remote arbitrary code execution has been confirmed.
It should be noted that although this vulnerability has been reported to affect IglooFTP PRO version 3.8, other versions might also be affected.
IglooFTP PRO for Windows platforms has been reported prone to multiple buffer overrun vulnerabilities.
The issue likely presents itself due do a lack of sufficient bounds checking performed on data that is copied into a reserved internal memory buffer. Remote arbitrary code execution has been confirmed.
It should be noted that although this vulnerability has been reported to affect IglooFTP PRO version 3.8, other versions might also be affected.
Exploit / POC
IglooFTP PRO Multiple Buffer Overflow Vulnerabilities
The following exploits have been provided.
The following exploits have been provided.