vendor:
FTP Voyager
by:
Abdullah Alıç
7.8
CVSS
HIGH
Denial of Service
119
CWE
Product Name: FTP Voyager
Affected Version From: 16.2.0
Affected Version To: 16.2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:serv-u:ftp_voyager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP Professional sp3 (ENG)
2018
FTP Voyager 16.2.0 – Denial of Service (PoC)
A buffer overflow vulnerability exists in FTP Voyager 16.2.0, which could allow an attacker to cause a denial of service condition. The vulnerability is due to improper bounds checking of user-supplied data, which can be exploited by an attacker to cause a stack-based buffer overflow by sending a specially crafted request to the vulnerable application. An attacker can send a specially crafted request containing an overly long string to trigger this vulnerability.
Mitigation:
Upgrade to the latest version of FTP Voyager 16.2.0 or later.