4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
BID:8601
Info
4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
| Bugtraq ID: | 8601 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2003 12:00AM |
| Updated: | Sep 12 2003 12:00AM |
| Credit: | This vulnerability was reported by B-r00t <[email protected]>. |
| Vulnerable: |
4D WebSTAR 5.3.1 4D WebSTAR 5.3 4D WebSTAR 5.2.4 4D WebSTAR 5.2.3 4D WebSTAR 5.2.2 4D WebSTAR 5.2.1 4D WebSTAR 5.2 |
| Not Vulnerable: | |
Discussion
4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
A buffer overrun has been reported for 4D WebSTAR FTP. The problem is said to occur due to insufficient bounds checking when handling excessive data passed within the PASS command. As a result, an attacker may be capable of corrupting sensitive data adjacent to the allocated storage buffer, potentially allow for the execution of arbitrary code.
It should be noted that this issue could be exploited by an unauthenticated attacker, as the issue occurs during the pre-authentication phase.
A buffer overrun has been reported for 4D WebSTAR FTP. The problem is said to occur due to insufficient bounds checking when handling excessive data passed within the PASS command. As a result, an attacker may be capable of corrupting sensitive data adjacent to the allocated storage buffer, potentially allow for the execution of arbitrary code.
It should be noted that this issue could be exploited by an unauthenticated attacker, as the issue occurs during the pre-authentication phase.
Exploit / POC
4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
4D WebSTAR FTP Remote Long Password Buffer Overrun Vulnerability
References:
References:
- 4D Inc. Homepage (4D Inc.)