vendor:
TFTP Service
by:
Umesh Wanve
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: TFTP Service
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4 Server English, Windows 2000 SP4 Professional English
2007
3Com TFTP Service <= 2.0.1 (Long Transporting Mode) Overflow Perl Exploit
Buffer overflow exists in transporting mode name of TFTP server. Buffer = "x00x02" + "filename" + "x00" + nop sled + Shellcode + JUMP + "x00";
Mitigation:
Upgrade to a patched version of the 3Com TFTP Service.