Title: WarFTPd Username Handling Remote Format String DoS
Info
Disclosure
Aug 31, 2012
Discovery
Unknown
Dates
Exploit
Aug 31, 2012
Solution
Unknown
Description
WarFTPd contains a format string flaw in war-ftpd.exe. The issue is triggered as format string specifiers (e.g. %s and %x) are not properly sanitized in usernames supplied during the authentication process. With a specially crafted request, a remote attacker can crash the service causing a denial of service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability.