vendor:
TFTPD32
by:
MC
7.5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: TFTPD32
Affected Version From: TFTPD32 version 2.21 and prior
Affected Version To: TFTPD32 version 2.21
Patch Exists: NO
Related CWE: CVE-2002-2226
CPE: a:tftpd32_project:tftpd32:2.21
Platforms Tested: Windows
2002
TFTPD32 <= 2.21 Long Filename Buffer Overflow
This module exploits a stack buffer overflow in TFTPD32 version 2.21 and prior. By sending a request for an overly long file name to the tftpd32 server, a remote attacker could overflow a buffer and execute arbitrary code on the system.
Mitigation:
Update to a patched version of TFTPD32.