|
|
| |
| A Remote Code Execution vulnerability was discovered in Novell Netware FTP. |
| |
Credit:
The information has been provided by Francis Provencher.
The original article can be found at: http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=12&Itemid=12
|
| |
Vulnerable Systems:
* Novell Netware 6.5 SP8
It's possible to overflow the stack and rewrite the EIP by sending a mkdir and a rmdir request with these special caracters "~A/" 320 time.
CVE Information:
CVE-2010-0625
Disclosure Timeline:
2010-01-25 Vendor Contact
2010-01-26 Vendor repsonse
2010-03-26 Coordinate release of this advisory
|
|
blog comments powered by
|