PT-2006-3221 · Filecopa · Filecopa
Publicado
2006-05-09
·
Atualizado
2017-07-20
·
CVE-2006-2254
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FileCOPA version 1.01
Description
The issue is related to a buffer overflow in the filecpnt.exe component, which can be triggered by a remote attacker sending a username with a large number of newline characters. This results in a denial of service, causing the application to crash.
Recommendations
For FileCOPA version 1.01, consider restricting the input length for usernames to prevent the buffer overflow until a patch is available. As a temporary workaround, limit the number of newline characters allowed in usernames to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Filecopa