OSVDB ID: 85934

Title: WarFTPd Username Handling Remote Format String DoS

Info

Disclosure

Aug 31, 2012

Discovery

Unknown

Dates

Exploit

Aug 31, 2012

Solution

Unknown

Description

WarFTPd contains a format string flaw in war-ftpd.exe. The issue is triggered as format string specifiers (e.g. %s and %x) are not properly sanitized in usernames supplied during the authentication process. With a specially crafted request, a remote attacker can crash the service causing a denial of service.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Availability
Solution: Solution Unknown
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure

Solution

OSVDB is not aware of a solution for this vulnerability.

Products

WarFTP

WarFTPd

1.82 RC 11
1.82 RC 12
1.82 RC 13

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85934