PT-2004-2782 · Ipswitch · Ipswitch Ws Ftp Server

Hugh Mann

·

Publicado

2004-12-31

·

Atualizado

2023-10-11

·

CVE-2004-1883

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ipswitch WS FTP Server version 4.0.2
Description The issue involves multiple buffer overflows that allow remote authenticated users to execute arbitrary code. This can be achieved by causing a large error string to be generated by the ALLO handler or by inserting a long hostname or username into a reply to a STAT command while a file is being transferred.
Recommendations For Ipswitch WS FTP Server version 4.0.2, consider disabling the ALLO handler and restricting access to the STAT command as temporary workarounds until a patch is available. Restrict access to the server to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1883

Produtos afetados

Ipswitch Ws Ftp Server