Overview
There is a buffer overflow vulnerability in the FileCOPA FTP server which may allow an attacker to execute arbitrary code.
Description
FileCOPA is an FTP server for Microsoft Windows that supports anonymous file transfers. There is a buffer overflow vulnerability in the FileCOPA FTP service (filecpnt.exe) that may occur when malformed input is passed to the server using common FTP commands. If anonymous connections to the server are allowed, an attacker would not need valid user credentials to exploit this vulnerability. |
Impact
A remote, unauthenticated attacker may execute arbitrary code. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Carsten Eiram, Secunia Research for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-3768 |
Severity Metric: | 1.03 |
Date Public: | 2006-07-25 |
Date First Published: | 2006-09-29 |
Date Last Updated: | 2006-09-29 14:03 UTC |
Document Revision: | 27 |