Vulnerabilities > CVE-2005-0696 - Remote Buffer Overrun vulnerability in Argosoft FTP Server 1.4.2.29/1.4.2.8/1.4.3.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | FTP |
NASL id | ARGOSOFT_FTP_DELE_OVERFLOW.NASL |
description | According to its banner, the version of ArGoSoft FTP Server installed on the remote host is affected by a heap-based buffer overflow that can be triggered by a malicious user with delete rights who issues a DELE command with an argument exceeding 2000 characters. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17303 |
published | 2005-03-09 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17303 |
title | ArGoSoft FTP Server DELE Command Remote Buffer Overrun |
code |
|
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042523.html
- http://secunia.com/advisories/14526
- http://securityreason.com/securityalert/494
- http://securitytracker.com/id?1015681
- http://www.securityfocus.com/archive/1/392653
- http://www.securityfocus.com/archive/1/426081/100/0/threaded
- http://www.securityfocus.com/bid/12755
- https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html