vendor:
AT-TFTP Server
by:
Liu Qixu Of NCNIPC
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AT-TFTP Server
Affected Version From: v1.9
Affected Version To: v1.9
Patch Exists: YES
Related CWE: N/A
CPE: a:allied_telesyn:at-tftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2006
AT-TFTP Server v1.9 Buffer Overflow Vulnerability
A vulnerability has been identified in TFTP Server AT-TFTP Server v1.9, which could be exploited by remote or local attackers to execute arbitrary commands or cause a denial of service. This flaw is due to a buffer overflow error when handling an overly long file name (more than 227 bytes) passed to a 'GET' or 'PUT' command, which could be exploited by malicious users to compromise a vulnerable system or crash an affected application.
Mitigation:
Upgrade to the latest version of AT-TFTP Server.