Release date:
Updated on:
Affected Systems:
CertificationKits CiscoKits ccna tftp Server 1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49045
CiscoKits ccna tftp Server is a multi-threaded Cisco IOS upgrade, file backup, Cisco certification exam preparation, upload and download IOS graphics and configuration tools.
CiscoKits ccna tftp Server has a denial of service vulnerability in the processing of Write commands, which can be exploited by malicious users to crash the affected applications.
<* Source: SecPod Research
Link: http://www.exploit-db.com/exploits/17618/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
49053. py
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
CertificationKits
-----------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.certificationkits.com/cisco-ccna-tftp-server/