WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=107801142924976&w=2 | mailing list |
http://www.osvdb.org/4116 | vdb entry broken link |
http://secunia.com/advisories/11001 | third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15342 | vdb entry third party advisory |
http://www.securityfocus.com/bid/9767 | patch vendor advisory exploit vdb entry third party advisory broken link |