Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument to the (2) MKD, (3) XMKD, (4) RMD, and other unspecified commands in the FTP component.
References
Configurations
History
21 Nov 2024, 00:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0007.html - | |
References | () http://secunia.com/advisories/32892 - Vendor Advisory | |
References | () http://www.maxum.com/Rumpus/News601.html - | |
References | () http://www.securityfocus.com/archive/1/498786/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/32558 - Exploit | |
References | () http://www.securityfocus.com/bid/32560 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/46987 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/46988 - | |
References | () https://www.exploit-db.com/exploits/7314 - |
Information
Published : 2009-08-25 10:30
Updated : 2024-11-21 00:58
NVD link : CVE-2008-7078
Mitre link : CVE-2008-7078
CVE.ORG link : CVE-2008-7078
JSON object : View
Products Affected
maxum
- rumpus
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer