First published: Fri Dec 01 2006(Updated: )
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3com 3ctftpsvc | <=2.0.1 | |
3Com 3CTftpSvc | <=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6183 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2006-6183, upgrade 3Com 3CTftpSvc to the latest version beyond 2.0.1, if available.
CVE-2006-6183 enables remote attackers to exploit stack-based buffer overflows leading to crashes or arbitrary code execution.
CVE-2006-6183 affects version 2.0.1 and possibly earlier versions of 3Com 3CTftpSvc.
Yes, CVE-2006-6183 can be exploited remotely via specially crafted GET or PUT commands.