CVE-2006-4847: Buffer Overflow
Published Sep 19, 2006
·Updated
Multiple buffer overflows in Ipswitch WSFTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
Affected Software
48 affected components
Ipswitch Ws Ftp Server=5.02
Ipswitch Ws Ftp Server=4.01
Ipswitch Ws Ftp Server=3.0_1
Ipswitch Ws Ftp Server=1.0.1eval
Ipswitch Ws Ftp Server=5.03
Ipswitch Ws Ftp Server=1.0.2eval
Progress Ipswitch Ws Ftp Server=1.0.1
Progress Ipswitch Ws Ftp Server=1.0.1.e
Progress Ipswitch Ws Ftp Server=1.0.2
Progress Ipswitch Ws Ftp Server=1.0.2.e
Progress Ipswitch Ws Ftp Server=1.0.3
Progress Ipswitch Ws Ftp Server=1.0.4
Progress Ipswitch Ws Ftp Server=1.0.5
Progress Ipswitch Ws Ftp Server=2.0
Progress Ipswitch Ws Ftp Server=2.0.1
Progress Ipswitch Ws Ftp Server=2.0.2
Progress Ipswitch Ws Ftp Server=2.0.3
Progress Ipswitch Ws Ftp Server=2.0.4
Progress Ipswitch Ws Ftp Server=3.0
Progress Ipswitch Ws Ftp Server=3.1
Progress Ipswitch Ws Ftp Server=3.1.1
Progress Ipswitch Ws Ftp Server=3.1.2
Progress Ipswitch Ws Ftp Server=3.1.3
Progress Ipswitch Ws Ftp Server=3.4
Progress Ipswitch Ws Ftp Server=4.0
Progress Ipswitch Ws Ftp Server=4.0.2
Progress Ipswitch Ws Ftp Server<=5.05
Progress Ws Ftp Server<=5.05
Progress Ws Ftp Server=1.0.1
Progress Ws Ftp Server=1.0.1.e
Progress Ws Ftp Server=1.0.2
Progress Ws Ftp Server=1.0.2.e
Progress Ws Ftp Server=1.0.3
Progress Ws Ftp Server=1.0.4
Progress Ws Ftp Server=1.0.5
Progress Ws Ftp Server=2.0
Progress Ws Ftp Server=2.0.1
Progress Ws Ftp Server=2.0.2
Progress Ws Ftp Server=2.0.3
Progress Ws Ftp Server=2.0.4
Progress Ws Ftp Server=3.0
Progress Ws Ftp Server=3.1
Progress Ws Ftp Server=3.1.1
Progress Ws Ftp Server=3.1.2
Progress Ws Ftp Server=3.1.3
Progress Ws Ftp Server=3.4
Progress Ws Ftp Server=4.0
Progress Ws Ftp Server=4.0.2
Remediation
Patch Available
Event History
Sep 19, 2006
CVE Published
01:07 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4847?
The severity of CVE-2006-4847 is considered to be critical due to the potential for remote code execution.
2
How do I fix CVE-2006-4847?
To fix CVE-2006-4847, you need to update to Ipswitch WS_FTP Server version 5.05 Hotfix 1 or later.
3
Who is affected by CVE-2006-4847?
CVE-2006-4847 affects multiple versions of Ipswitch WS_FTP Server prior to Hotfix 1.
4
What types of commands can exploit CVE-2006-4847?
CVE-2006-4847 can be exploited through long XCRC, XSHA1, or XMD5 commands.
5
What are the risks associated with CVE-2006-4847?
The risks associated with CVE-2006-4847 include unauthorized remote execution of arbitrary code on affected systems.