CVE-2008-7078 Information

Description

Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument to the (2) MKD (3) XMKD (4) RMD and other unspecified commands in the FTP component.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0007.html http://secunia.com/advisories/32892 http://www.maxum.com/Rumpus/News601.html http://www.securityfocus.com/archive/1/498786/100/0/threaded http://www.securityfocus.com/bid/32558 http://www.securityfocus.com/bid/32560 https://exchange.xforce.ibmcloud.com/vulnerabilities/46987 https://exchange.xforce.ibmcloud.com/vulnerabilities/46988 https://www.exploit-db.com/exploits/7314

Share on: