Cybertrion Systems

[3/5] TFTP Server SP Long Filename Buffer Overflow Vulnerability

March 28th, 2008 by
[3/5] TFTP Server SP Long Filename Buffer Overflow Vulnerability

:Mati Aharoni has discovered a vulnerability in TFTP Server SP, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.The vulnerability is caused due to a boundary error in the handling of filenames and can be exploited to cause a stack-based buffer overflow via a read or write request with an overly long filename.Successful exploitation allows execution of arbitrary code.The vulnerability is confirmed in the Windows version of TFTP Server SP version 1.4. Other versions may also be affected.Solution:Restrict network access to the TFTP service.Provided and/or discovered by:Mati AharoniOriginal Advisory:http://www.offensive-security.com/0day/sourceforge-tftpd.py.txt

Original post by kapil

[3/5] TFTP Server SP Long Filename Buffer Overflow Vulnerability

Related Articles:
  • [3/5] BootManage TFTP Server Buffer Overflow Vulnerability
  • [3/5] TFTP Server SP Long Error Message Buffer Overflow
  • [3/5] Quick Tftp Server Pro Long Mode Buffer Overflow Vulnerability
  • [2/5] PacketTrap pt360 TFTP Filename Handling Denial of Service
  • [2/5] Acronis Snap Deploy PXE Server TFTP Vulnerabilities


  • Posted in Advisories - Exploits | | [3/5] TFTP Server SP Long Filename Buffer Overflow Vulnerability

    << [3/5] Ubuntu update for sdl-image | [3/5] eggBlog Unspecified Cookie SQL Injection >>