Short Name |
TFTP:FS-FILE |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
TFTP |
Keywords |
Format String In Filename |
Release Date |
2011/02/09 |
Update Number |
1862 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against multiple TFTP servers. A successful attack can lead to arbitrary code execution.
A remote format-string vulnerability affects Tftpd32. This issue presents itself when the TFTP server attempts to process specially crafted data through the SEND or GET commands. A remote attacker may leverage this issue to execute arbitrary code in the context of the server. Tftpd32 2.81 is reportedly vulnerable. Other versions may be affected as well.