Tuesday, December 5, 2006

Mac OS X ftpd Buffer Overflow Vulnerability

A vulnerability has been reported in Mac OS X, which potentially can be exploited by malicious users to compromise a vulnerable system.

The vulnerability is caused due to a boundary error in ftpd when handling commands with globbing characters (e.g. "*") and can be exploited to cause a buffer overflow.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in Mac OS X 10.3.9 and 10.4.8. Other versions may also be affected.

http://secunia.com/advisories/23178/

No comments:

Post a Comment