Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:36:28 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1615104650&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0911-advisories%2Fsecunia-servutea.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1615104650.1338186988.1338186988.1338186988.1%3B%2B__utmz%3D32867617.1338186988.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) RhinoSoft Serv-U TEA Decoding Buffer Overflow http://packetstormsecurity.org/files/82789/secunia-servutea.txt http://packetstormsecurity.org/files/82789/secunia-servutea.txt http://packetstormsecurity.org/files/82789/RhinoSoft-Serv-U-TEA-Decoding-Buffer-Overflow.html Wed, 18 Nov 2009 23:17:01 GMT Secunia Research has discovered a vulnerability in Serv-U, which can be exploited by malicious people to potentially compromise a vulnerable system. The vulnerability is caused by a boundary error in a function when processing a hexadecimal representation of a string using a TEA decoding algorithm. This can be exploited to cause a stack-based buffer overflow by passing an overly long string. Successful exploitation may allow execution of arbitrary code. Version 9.0.0.5 is affected.