TurboSoft TurboFTP Receive Buffer Overflow Vulnerability
BID:8163
Info
TurboSoft TurboFTP Receive Buffer Overflow Vulnerability
| Bugtraq ID: | 8163 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 10 2003 12:00AM |
| Updated: | Jul 10 2003 12:00AM |
| Credit: | Vulnerability reported by Peter Winter-Smith <[email protected]>. |
| Vulnerable: |
TurboSoft TurboFTP 3.85 Build 304 |
| Not Vulnerable: | |
Discussion
TurboSoft TurboFTP Receive Buffer Overflow Vulnerability
TurboFTP has been reported prone to a buffer overflow vulnerability.
It may be possible to crash the FTP client by sending a large response from the server to a vulnerable client. The issue likely presents itself due do a lack of sufficient bounds checking performed on data that is copied into a reserved internal memory buffer. This could result in a denial of service. It is not known whether arbitrary code execution is possible.
TurboFTP has been reported prone to a buffer overflow vulnerability.
It may be possible to crash the FTP client by sending a large response from the server to a vulnerable client. The issue likely presents itself due do a lack of sufficient bounds checking performed on data that is copied into a reserved internal memory buffer. This could result in a denial of service. It is not known whether arbitrary code execution is possible.
Solution / Fix
TurboSoft TurboFTP Receive Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.