Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Link | Tags |
---|---|
http://www.nai.com/research/covert/advisories/048.asp | vendor advisory broken link |
http://www.cert.org/advisories/CA-2001-07.html | us government resource third party advisory patch |
http://www.securityfocus.com/bid/2550 | patch vendor advisory vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6332 | vdb entry third party advisory |