PT-2002-1648 · Kth · Kth Kerberos 4 Ftp Client
Published
2002-06-11
·
Updated
2008-09-10
·
CVE-2002-0600
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KTH Kerberos 4 FTP client version 4-1.1.1
Description
The issue is related to a heap overflow in the KTH Kerberos 4 FTP client. This allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
Recommendations
For version 4-1.1.1, consider disabling the use of passive mode until a patch is available. Restrict access to untrusted FTP servers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kth Kerberos 4 Ftp Client