PT-1999-1772 · Qpc · Qvt/Term Plus+1
Published
1999-11-10
·
Updated
2017-12-19
·
CVE-1999-1539
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
QVT/Term Plus versions 4.2d through 4.3
QVT/Net version 4.3
Description:
A buffer overflow issue in the FTP server of QPC Software's products allows remote attackers to cause a denial of service and possibly execute arbitrary commands by providing a long
username or password.Recommendations:
For QVT/Term Plus versions 4.2d through 4.3, consider disabling the FTP server functionality until a patch is available.
For QVT/Net version 4.3, restrict access to the FTP server to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qvt/Net
Qvt/Term Plus