vendor:
Netware NWFTPD.NLM
by:
shahin [at] abysssec.com , info [at] abysssec.com
9
CVSS
CRITICAL
Buffer Overflow
120
CWE
Product Name: Netware NWFTPD.NLM
Affected Version From: NWFTPD.NLM 5.09.02 (Netware 6.5 SP8)
Affected Version To: NWFTPD.NLM 5.09.02 (Netware 6.5 SP8)
Patch Exists: Unknown
Related CWE: Unknown
CPE: Novell:Netware:NWFTPD.NLM
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
Unknown
Novell Netware NWFTPD RMD/RNFR/DELE Argument Parsing Buffer overflow
A buffer overflow vulnerability exists in Novell Netware NWFTPD.NLM 5.09.02 (Netware 6.5 SP8). A remote attacker can send a specially crafted DELE command with an overly long argument to trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of Novell Netware NWFTPD.NLM 5.09.02 (Netware 6.5 SP8)