Vyatta –
Linux & Open Source
Alternative to Cisco –
Advanced Routing,
Firewall, VPN, QoS..
Free Download ->
|
|
| |
|
| |
glFTPd: Local buffer overflow vulnerability
| Package(s): | glFTPd |
CVE #(s): | |
| Created: | September 21, 2004 |
Updated: | September 22, 2004 |
| Description: |
The glFTPd server is vulnerable to a buffer overflow in the 'dupescan'
program. This vulnerability is due to an unsafe strcpy() call which can
cause the program to crash when a large argument is passed. A local user
with malicious intent can pass a parameter to the dupescan program that
exceeds the size of the buffer, causing it to overflow. This can lead the
program to crash, and potentially allow arbitrary code execution with the
permissions of the user running glFTPd, which could be the root user. |
| Alerts: |
|
( Log in to post comments)
|
|
|