Summary
TFTPDWIN server is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code in the context of the TFTP server process.
TFTPDWIN 0.4.2 is vulnerable
other versions may be affected as well.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2006-4948 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities