漏洞信息详情
SmartFTP PWD命令请求缓冲区溢出漏洞
- CNNVD编号:CNNVD-200312-469
- 危害等级: 高危
- CVE编号:
CVE-2003-1319
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-12-31
- 威胁类型:
远程
- 更新时间:
2007-03-07
- 厂 商:
smartftp - 漏洞来源:
Discovery is credi… -
漏洞简介
SmartFTP 1.0.973及其1.0.976以前版本存在多个缓冲区溢出漏洞。远程攻击者可以借助(1)引起基于栈的缓冲区溢出的PWD 命令超长响应,和(2)引起基于堆的缓冲区溢出的文件LIST命令超长行响应来执行任意代码。
漏洞公告
This issue was reportedly corrected in SmartFTP 1.0.976, however, this has not been confirmed by Symantec.
SmartFTP SmartFTP 1.0.973
-
SmartFTP SmartFTP 1.0.976
http://www.smartftp.com/download/
参考网址
来源: XF
名称: smartftp-long-list-bo(12231)
链接:http://xforce.iss.net/xforce/xfdb/12231
来源: XF
名称: smartftp-pwd-directory-bo(12228)
链接:http://xforce.iss.net/xforce/xfdb/12228
来源: BID
名称: 7861
链接:http://www.securityfocus.com/bid/7861
来源: BID
名称: 7858
链接:http://www.securityfocus.com/bid/7858
来源: SECUNIA
名称: 8998
链接:http://secunia.com/advisories/8998
来源: SECTRACK
名称: 1006956
链接:http://securitytracker.com/id?1006956
来源: security.nnov.ru
链接:http://security.nnov.ru/docs4679.html
来源: BUGTRAQ
名称: 20030608 [SmartFTP] Two Buffer Overflow Vulnerabilities
链接:http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html