Vulnerabilities > CVE-2006-4781 - Remote Denial Of Service vulnerability in Futuresoft Tftp Server Multithreaded 1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
futuresoft
exploit available

Summary

Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Futuresoft
1

Exploit-Db

descriptionMultithreaded TFTP. CVE-2006-4781. Dos exploit for windows platform
fileexploits/windows/dos/2334.py
idEDB-ID:2334
last seen2016-01-31
modified2006-09-08
platformwindows
port
published2006-09-08
reportern00b
sourcehttps://www.exploit-db.com/download/2334/
titleMultithreaded TFTP <= 1.1 - Long Get Request Denial of Service Exploit
typedos