PT-2006-3221 · Filecopa · Filecopa
Published
2006-05-09
·
Updated
2017-07-20
·
CVE-2006-2254
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FileCOPA version 1.01
Description
The issue is related to a buffer overflow in the filecpnt.exe component, which can be triggered by a remote attacker sending a username with a large number of newline characters. This results in a denial of service, causing the application to crash.
Recommendations
For FileCOPA version 1.01, consider restricting the input length for usernames to prevent the buffer overflow until a patch is available. As a temporary workaround, limit the number of newline characters allowed in usernames to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filecopa