cftp Banner Parsing Buffer Overflow Vulnerability
BID:8160
Info
cftp Banner Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 8160 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 10 2003 12:00AM |
| Updated: | Jul 10 2003 12:00AM |
| Credit: | Discovery credited to "inv[at]dtors". |
| Vulnerable: |
cftp cftp 0.12 |
| Not Vulnerable: | |
Discussion
cftp Banner Parsing Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported in cftp. The vulnerability occurs when cftp is parsing 'Welcome' banner messages from remote FTP servers. When cftp receives an FTP banner exceeding a certain length, it will trigger the overflow condition. This could allow for execution of malicious code in the context of the FTP client.
A buffer overflow vulnerability has been reported in cftp. The vulnerability occurs when cftp is parsing 'Welcome' banner messages from remote FTP servers. When cftp receives an FTP banner exceeding a certain length, it will trigger the overflow condition. This could allow for execution of malicious code in the context of the FTP client.
Exploit / POC
cftp Banner Parsing Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available: