Overview
BlackJumboDog fails to verify the length of several FTP commands, creating a buffer overflow vulnerability. Exploitation of this vulnerability may result in code execution on the target system with privileges of the FTP service.
Description
| BlackJumboDog is a multi-function server for Microsoft Windows, providing FTP, email, web, and proxy services. Version 3.6.1 contains a buffer overflow vulnerability. BlackJumboDog fails to check the length of FTP commands passed to it. Using specially crafted FTP commands, a remote user can trigger a buffer overflow condition and possibly execute code on the server. | 
Impact
| A remote attacker may be able to exploit this vulnerability to compromise the BlackJumboDog system. | 
Solution
| This issue has been resolved in version 3.6.2 of BlackJumboDog. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to Secunia, Tan Chew Keong, and SIG^2 for the information contained in their security advisories
This document was written by Will Dormann.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 3.38 | 
| Date Public: | 2004-08-02 | 
| Date First Published: | 2004-08-03 | 
| Date Last Updated: | 2005-04-14 18:09 UTC | 
| Document Revision: | 14 |