CVE-2007-5256

Mcdu Fsd - Memory Corruption

Title source: rule

Description

Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary code via a long HELP command on TCP port 3010 to the sysuser::exechelp function in sysuser.cc and (2) remote authenticated users to execute arbitrary code via long commands on TCP port 6809 to the servinterface::sendmulticast function in servinterface.cc, as demonstrated by a PIcallsign command.

Exploits (3)

exploitdb WORKING POC VERIFIED
by weak · perlremotewindows
https://www.exploit-db.com/exploits/4484
exploitdb WORKING POC VERIFIED
by Luigi Auriemma · perlremotewindows
https://www.exploit-db.com/exploits/30627
exploitdb WORKING POC VERIFIED
by Luigi Auriemma · textdoswindows
https://www.exploit-db.com/exploits/30628

Scores

EPSS 0.4166
EPSS Percentile 97.4%

Details

CWE
CWE-119
Status published
Products (2)
mcdu/fsd 2.052_d9
mcdu/fsd 3.000_d9
Published Oct 06, 2007
Tracked Since Feb 18, 2026