Vulnerabilities > CVE-2007-0020 - Remote Heap Overflow vulnerability in Transmit 3

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
panic-transmit
critical
exploit available

Summary

Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.

Vulnerable Configurations

Part Description Count
Application
Panic_Transmit
1

Exploit-Db

descriptionTransmit.app <= 3.5.5 ftps:// URL Handler Heap Buffer Overflow PoC. CVE-2007-0020. Dos exploit for osx platform
fileexploits/osx/dos/3160.html
idEDB-ID:3160
last seen2016-01-31
modified2007-01-20
platformosx
port
published2007-01-20
reporterMoAB
sourcehttps://www.exploit-db.com/download/3160/
titleTransmit.app <= 3.5.5 ftps:// URL Handler Heap Buffer Overflow PoC
typedos