vendor:
Udisk FTP Basic Edition
by:
Steven Seeley (mr_me)
7,5
CVSS
HIGH
Remote Denial of Service (DoS)
119
CWE
Product Name: Udisk FTP Basic Edition
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Iphone 3G - firmware 3.1.2 (Darwin kernel)
2010
Apple Iphone/Ipod – Udisk FTP Basic Edition Remote 0day DOS exploit
This exploit is a remote denial of service (DoS) vulnerability in the Apple Iphone/Ipod Udisk FTP Basic Edition application. The vulnerability is caused due to a boundary error when handling user supplied data, which can be exploited to cause a stack-based buffer overflow by sending an overly long username and password to the application. This can potentially allow remote attackers to crash the application, denying service to legitimate users.
Mitigation:
Upgrade to the latest version of the application.