|
|
|
![]() |
Vulnerability Note VU#857846Ability Server vulnerable to buffer overflowOverviewA buffer overflow in the Ability Server may allow remote authenticated attackers to execute arbitrary code.I. DescriptionA lack of input validation in Ability Server's FTP STOR command may allow a buffer overflow to occur. A remote authenticated attacker may be able to exploit this vulnerability by supplying the Ability Server with a specially crafted FTP STOR command.According to reports, Ability Server versions 2.34, 2.25. and 2.32 are vulnerable. However, other versions may also be affected. Block or Restrict Access Upgrade The Ability Server has been discontinued. Ability Server users are encouraged to upgrade to the Ability FTP Server to correct this issue.
References
This vulnerability was publicly reported in a Security Tracker Advisory.
This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||