Bounce vulnerability in SpoonFTP 1.1.0.1

From: Arne Vidstrom (arne.vidstrom@ntsecurity.nu)
Date: 01/20/02


From: "Arne Vidstrom" <arne.vidstrom@ntsecurity.nu>
To: <bugtraq@securityfocus.com>
Date: Sun, 20 Jan 2002 03:05:32 +0100

The vulnerability:

The FTP server is vulnerable to the FTP bounce attack, even against ports
lower than 1024.

Vendor Response:

Pi-Soft have created a new version that among other things fix this
vulnerability. Their response was very nice and quick.

/Arne Vidstrom, http://ntsecurity.nu



Relevant Pages

  • Bounce vulnerability in SpoonFTP 1.1.0.1
    ... The vulnerability: ... The FTP server is vulnerable to the FTP bounce attack, ... Vendor Response: ...
    (NT-Bugtraq)
  • RE: CDE libDtHelp LOGNAME Buffer Overflow Vulnerability
    ... CDE libDtHelp LOGNAME Buffer Overflow Vulnerability ... CDE can allow local attackers to gain root privileges. ... 03/04/2004 iDEFENSE clients notified ... 04/19/2004 Initial vendor response ...
    (Bugtraq)
  • [UNIX] Album.pl Vulnerable to Remote Command Execution
    ... housewarming rates on automated network vulnerability ... Vendor Response: ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [Full-disclosure] Drupal 6 Email Field XSS Vulnerability
    ... Vendor Response: See below ... Details of this vulnerability are also posted at the public URL ... The Email Field module contains a cross site scripting vulnerability due ... Log in as a user with 'Administer content types' privilege ...
    (Full-Disclosure)
  • [ Rosiello Security ] Eterm-LibAST Advisory
    ... By exploiting this vulnerability an attacker can gain control of the return address of the executing function allowing arbitrary code execution with "utmp" group privileges. ... Initial Vendor Response ... Johnny Mast from Rosiello Security is credited with discovering this vulnerability. ...
    (Bugtraq)

Loading