Vulnerabilities > CVE-2003-1319 - Unspecified vulnerability in Smartftp
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN smartftp
nessus
Summary
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | SMARTFTP_OVERFLOW.NASL |
description | The remote host is running SmartFTP - an FTP client. There is a flaw in the remote version of this software that could allow an attacker to execute arbitrary code on this host. To exploit it, an attacker would need to set up a rogue FTP server and have a user on this host connect to it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11709 |
published | 2003-06-10 |
reporter | This script is Copyright (C) 2003-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11709 |
title | SmartFTP Multiple Command Response Overflow |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html
- http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html
- http://secunia.com/advisories/8998
- http://secunia.com/advisories/8998
- http://security.nnov.ru/docs4679.html
- http://security.nnov.ru/docs4679.html
- http://securitytracker.com/id?1006956
- http://securitytracker.com/id?1006956
- http://www.securityfocus.com/bid/7858
- http://www.securityfocus.com/bid/7858
- http://www.securityfocus.com/bid/7861
- http://www.securityfocus.com/bid/7861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12228
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12228
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12231
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12231