Vigil@nce: AIX, buffer overflow of ftpd
September 2010 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/
SYNTHESIS OF THE VULNERABILITY
An attacker can use NLST in order to execute code.
Severity: 2/4
Creation date: 26/08/2010
DESCRIPTION OF THE VULNERABILITY
The NLST FTP command allow a user to list the content of a directory.
When a directory with lot of files is listed, a buffer overflow happen. Technical details are unknown.
An attacker can therefore use NLST in order to execute code.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN





News














