Description
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.
Problem types
CWE-134 Use of Externally-Controlled Format String
Product status
*
Credits
x000
C4SS!0 G0M3S
References
raw.githubusercontent.com/...os/windows/ftp/solarftp_user.rb
www.exploit-db.com/exploits/16204
web.archive.org/web/20111102141514/https://solarftp.com/
web.archive.org/...com/blog/news/solar-ftp-server-2-1-2.html
www.vulncheck.com/...ies/solar-ftp-server-malformed-user-dos