20040323 ALLO ALLO WS_FTP Servermailing list
http://marc.info/?l=bugtraq&m=108006553222397&w=2 CVE-2004-1883
Ipswitch WS_FTP Server 4.0.2 - ALLO Remote Buffer Overflow
Record summary
CVE-2004-1883 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIpswitch WS_FTP Server 4.0.2 - ALLO Remote Buffer OverflowExploitDB exploitby Hugh MannNot analyzed1 file
References
611206Third-party advisory
http://secunia.com/advisories/11206 20040323 Think of the buffers! Won't somebody think of the buffers?!mailing list
http://www.securityfocus.com/archive/1/358361 9953vdb entry
http://www.securityfocus.com/bid/9953 wsftp-allo-bo(15561)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15561 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1883