Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

HD Soft Windows FTP Server Username Format String Vulnerability

It has been reported that Windows FTP Server may be prone to a remote format string vulnerability when processing a malicious request from a client. The vulnerability presents itself when the server receives a malicious request containing embedded format string specifiers from a remote client when supplying a username during FTP authentication. This could be exploit to crash the server but could also theoretically permit corruption/disclosure of memory contents and execution of arbitrary code.

Windows FTP Server versions 1.6 and prior are reported to be prone to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus