TFTPD32 Buffer Overflow in Processing Filenames Allows Remote Users to Execute Arbitrary Code
Categorie: Vulnerability Posted: 2002-11-20 by ReCall Views: 374 Source: Click here
Current Rating: Not rated
Details
Description: A vulnerability was reported in the TFTPD32 TFTP server for Microsoft Windows-based platforms. A remote user can execute arbitrary code on the server.
SecuriTeam reported that a remote user can supply a long filename to the TFTP server to trigger the overflow and execute arbitrary code.
A demonstration exploit script is provided in the Source Message.
Impact: A remote user can execute arbitrary code on the server.
Solution: The vendor has released a fixed version (2.50.2), available at: