PT-2006-3221 · Filecopa · Filecopa

Published

2006-05-09

·

Updated

2017-07-20

·

CVE-2006-2254

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions FileCOPA version 1.01
Description The issue is related to a buffer overflow in the filecpnt.exe component, which can be triggered by a remote attacker sending a username with a large number of newline characters. This results in a denial of service, causing the application to crash.
Recommendations For FileCOPA version 1.01, consider restricting the input length for usernames to prevent the buffer overflow until a patch is available. As a temporary workaround, limit the number of newline characters allowed in usernames to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2254

Affected Products

Filecopa