![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.11184 |
Category: | Denial of Service |
Title: | vxworks ftpd buffer overflow Denial of Service |
Summary: | It was possible to make the remote host; crash by issuing a FTP command. |
Description: | Summary: It was possible to make the remote host crash by issuing a FTP command. Vulnerability Insight: It was possible to make the remote host crash by issuing this FTP command: CEL aaaa(...)aaaa This problem is similar to the 'aix ftpd' overflow but on embedded vxworks based systems like the 3com nbx IP phone call manager and seems to cause the server to crash. Affected Software/OS: This affects VxWorks ftpd versions 5.4 and 5.4.2. Solution: If you are using an embedded vxworks product, please contact the OEM vendor and reference WindRiver field patch TSR 296292. If this is the 3com NBX IP Phone call manager, contact 3com. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-2300 BugTraq ID: 6297 http://www.securityfocus.com/bid/6297 Bugtraq: 20021202 [VU#317417] Denial of Service condition in vxworks ftpd/3com nbx (Google Search) http://marc.info/?l=bugtraq&m=103886644126011&w=2 Bugtraq: 20030427 3com NBX IP Phone Call manager Denial of Service - Update (Google Search) http://seclists.org/lists/bugtraq/2003/Apr/0344.html CERT/CC vulnerability note: VU#317417 http://www.kb.cert.org/vuls/id/317417 http://www.secnap.com/alerts.php?pg=6 http://securitytracker.com/id?1005732 http://securitytracker.com/id?1006760 XForce ISS Database: 3com-nbx-cel-bo(10739) https://exchange.xforce.ibmcloud.com/vulnerabilities/10739 |
Copyright | Copyright (C) 2002 Michael Scheidell |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |