vendor:
Serv-U FTP Server
by:
bkbll
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Serv-U FTP Server
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Serv-U FTP Server Remote Stack Based Buffer Overflow Vulnerability
Serv-U FTP Server has been reported prone to a remote stack based buffer overflow vulnerability when handling time zone arguments passed to the MDTM FTP command. The problem exists due to insufficient bounds checking. Ultimately an attacker may leverage this issue to have arbitrary instructions executed in the context of the SYSTEM user.
Mitigation:
The vendor has not yet released a patch, so releasing such an exploit could be disastrous in the hands of script kiddies.