vendor:
TFTPDWIN Server
by:
Umesh Wanve
7.5
CVSS
HIGH
Arbitrary Command Execution or Denial of Service
CWE
Product Name: TFTPDWIN Server
Affected Version From: TFTPDWIN Server v0.4.2
Affected Version To: TFTPDWIN Server v0.4.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 9x/NT/XP
2007
TFTPDWIN Server UDP DOS 0.4.2 POC
The TFTPDWIN Server v0.4.2 is vulnerable to an attack where a remote or local attacker can execute arbitrary commands or cause a denial of service by sending a UDP packet of length more than 516 bytes.
Mitigation:
Update to a patched version of TFTPDWIN Server.