Description
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46371 (ExploitDB-46371)
www.coreftp.com/ (Official Product Homepage)
www.coreftp.com/.../download/archive/CoreFTPServer589.42.exe (Product Reference)
www.vulncheck.com/...r-denial-of-service-via-buffer-overflow (VulnCheck Advisory: Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow)