vendor:
Moxftp
by:
inv[at]dtors
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Moxftp
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:moxftp:moxftp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 4.7, FreeBSD 5.0
2002
Buffer Overflow Vulnerability in moxftp
A buffer overflow vulnerability has been reported for moxftp. The vulnerability occurs when moxftp is parsing 'Welcome' banner messages from remote FTP servers. When moxftp receives an overly long FTP banner, it will trigger the overflow condition. An attacker can exploit this vulnerability by enticing a victim moxftp user to connect to a malicious FTP server. Any attacker-supplied code will be executed on the victim system with the privileges of the moxftp process.
Mitigation:
Upgrade to the latest version of moxftp.