OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA11840] WinAgents TFTP Server Long Filename Request Denial of Service

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Jun 11 2004 - 09:18:28 CDT


TITLE:
WinAgents TFTP Server Long Filename Request Denial of Service

SECUNIA ADVISORY ID:
SA11840

VERIFY ADVISORY:
http://secunia.com/advisories/11840/

CRITICAL:
Less critical

IMPACT:
DoS

WHERE:
From local network

SOFTWARE:
WinAgents TFTP Server 3.x

DESCRIPTION:
Ziv Kamir has reported a vulnerability in WinAgents TFTP Server,
which can be exploited by malicious people to cause a DoS (Denial of
Service).

The vulnerability is caused due to an error during the request
handling. This can be exploited to crash the service by requesting an
overly long file name (about 1,000 bytes).

The vulnerability has been reported in version 3.0. Other versions
may also be affected.

SOLUTION:
The vendor will reportedly issue an update in a short time.

Restrict access to the service.

PROVIDED AND/OR DISCOVERED BY:
Ziv Kamir

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------