vendor:
TFTPD32/TFTPD64
by:
j0s3h4x0r
7,8
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: TFTPD32/TFTPD64
Affected Version From: 4.5 32 bits / 4.5 64 bits
Affected Version To: 4.5 32 bits / 4.5 64 bits
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64
2014
TFTPD32 4.5 / TFTPD64 4.5 DoS poc
This proof of concept code will crash TFTPD32 and TFTPD64. By changing the $j and $i loop limits, the EIP can reach 0x2E373231 ("127.") or any string contained in TFTPD32 error logs, and sometimes EIP reaches addresses similar to 0x00013200, which may enable Remote Code Execution using some form of heap-spray.
Mitigation:
N/A