community.microfocus.comConfirmation
http://community.microfocus.com/microfocus/mainframe_solutions/rumba/w/knowledge_base/28731.rumba-ftp-4-x-security-update.aspx CVE-2016-5764
HIGH
Rumba FTP Client 4.x - Remote Stack Buffer Overflow (SEH)
Record summary
CVE-2016-5764 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Micro Focus Rumba FTP 4.X before 4.5 (HF 14668) | CVE List | Micro Focus Rumba FTP 4.X before 4.5 (HF 14668) | affected |
Proofs of concept
1Catalogued exploits
ExploitDBRumba FTP Client 4.x - Remote Stack Buffer Overflow (SEH)ExploitDB exploitby Umit AksuNot analyzed1 file
References
493974vdb entry
http://www.securityfocus.com/bid/93974 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-5764 40651exploit
https://www.exploit-db.com/exploits/40651