Vulnerability Development mailing list archives

Re:FTP.EXE format string vulnerability


From: ByteRage <byterage () yahoo com>
Date: Sun, 10 Jun 2001 10:07:34 -0700 (PDT)


It probably *still* doesn't matter much, but I found
that the linux (Redhat 6.0 / Kernel 2.4.2) ftp client
is also vulnerable to format string vulnerabilities :

example :

site %x

NOTE : about my previous post : GET should've been a
command to the server, like RETR or STOR... however,
whether it's a working command or not, the format
string bug still occurs.

__________________________________________________
Do You Yahoo!?
Get personalized email addresses from Yahoo! Mail - only $35 
a year!  http://personal.mail.yahoo.com/


Current thread: