Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/25871 | patch vdb entry exploit |
http://secunia.com/advisories/27014 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2007/3311 | vdb entry |
https://www.exploit-db.com/exploits/4478 | exploit |
http://osvdb.org/41385 | vdb entry |
http://debork.se/poc/001_smbftpd.c | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36893 | vdb entry |
http://sourceforge.net/project/shownotes.php?release_id=543077 | patch |
http://www.securityfocus.com/archive/1/481220/100/0/threaded | mailing list |