PT-1999-1772 · Qpc · Qvt/Term Plus+1

Published

1999-11-10

·

Updated

2017-12-19

·

CVE-1999-1539

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: QVT/Term Plus versions 4.2d through 4.3 QVT/Net version 4.3
Description: A buffer overflow issue in the FTP server of QPC Software's products allows remote attackers to cause a denial of service and possibly execute arbitrary commands by providing a long username or password.
Recommendations: For QVT/Term Plus versions 4.2d through 4.3, consider disabling the FTP server functionality until a patch is available. For QVT/Net version 4.3, restrict access to the FTP server to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1539

Affected Products

Qvt/Net
Qvt/Term Plus