This application requires Javascript for optimal performance.

FTP.PASS.Command.Overflow

Alias(es)

FTP.Command.PASS.Overflow

Release Date

Sep 11, 2006

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

It indicates an attempt to exploit a buffer overflow vulnerability in BlackMoon FTP server. BlackMoon FTP server is designed for use with the Windows 2000 operating system. Due to inadequate user input sanitization, a remote attacker can cause a buffer overflow via specially-crafted FTP commands. Successful exploitation could allow remote attacker to execute arbitrary commands on a target system.

Affected Products

Any unprotected BlackMoon FTP server 1.0 to 1.5 is vulnerable to the attack.



Recommended Actions

Upgrade to BlackMoon FTP Server version 1.5.2 Build 1550 or newer.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-6576
CVE-1999-0256

Reference/s

http://www.securityfocus.com/bid/10078 (BugTraq)
http://www.securityfocus.com/bid/45957 (BugTraq)
http://www.securityfocus.com/bid/49427 (BugTraq)

Reference: VID-12762