[0day] 20041208 Ability Server 2.25 - 2.34 FTP => 'APPE' Buffer Overflow - PnK:: DCN3Tmailing list
http://lists.virus.org/dw-0day-0412/msg00004.html CVE-2004-1627
Ability Server 2.34 - 'APPE' Remote Buffer Overflow
Record summary
CVE-2004-1627 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAbility Server 2.34 - 'APPE' Remote Buffer OverflowExploitDB exploitby KaGraNot analyzed1 file
References
712941Third-party advisory
http://secunia.com/advisories/12941 1012464vdb entry
http://securitytracker.com/id?1012464 12347vdb entry
http://www.osvdb.org/12347 11508vdb entry
http://www.securityfocus.com/bid/11508 ability-appe-bo(18405)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18405 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1627