ID

VAR-200701-0065


CVE

CVE-2007-0201


TITLE

TIS Internet FWTK of ftp-gw Vulnerable to buffer overflow

Trust: 0.8

sources: JVNDB: JVNDB-2007-004934

DESCRIPTION

Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest). TIS Firewall Toolkit is prone to a remote buffer-overflow vulnerability because the software fails to properly check boundaries of user-supplied input prior to copying it to an insufficiently sized stack-based memory buffer. Other vulnerabilities may also be present, but this has not been confirmed

Trust: 1.98

sources: NVD: CVE-2007-0201 // JVNDB: JVNDB-2007-004934 // BID: 21960 // VULHUB: VHN-23563

AFFECTED PRODUCTS

vendor:tismodel:internet firewall toolkitscope:lteversion:2.1

Trust: 1.0

vendor:tismodel:internet firewall toolkitscope:eqversion:2.1

Trust: 0.9

vendor:tismodel:internet firewall toolkitscope: - version: -

Trust: 0.8

vendor:tismodel:internet firewall toolkitscope:eqversion:0

Trust: 0.3

sources: BID: 21960 // JVNDB: JVNDB-2007-004934 // CNNVD: CNNVD-200701-138 // NVD: CVE-2007-0201

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-0201
value: HIGH

Trust: 1.0

NVD: CVE-2007-0201
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200701-138
value: CRITICAL

Trust: 0.6

VULHUB: VHN-23563
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-0201
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-23563
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-23563 // JVNDB: JVNDB-2007-004934 // CNNVD: CNNVD-200701-138 // NVD: CVE-2007-0201

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-0201

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200701-138

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200701-138

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-004934

PATCH

title:Top Pageurl:http://www.fwtk.org/main.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-004934

EXTERNAL IDS

db:NVDid:CVE-2007-0201

Trust: 2.5

db:BIDid:21960

Trust: 2.0

db:OSVDBid:35967

Trust: 1.7

db:SECTRACKid:1017481

Trust: 1.7

db:JVNDBid:JVNDB-2007-004934

Trust: 0.8

db:CNNVDid:CNNVD-200701-138

Trust: 0.7

db:XFid:31363

Trust: 0.6

db:VULHUBid:VHN-23563

Trust: 0.1

sources: VULHUB: VHN-23563 // BID: 21960 // JVNDB: JVNDB-2007-004934 // CNNVD: CNNVD-200701-138 // NVD: CVE-2007-0201

REFERENCES

url:http://www.ranum.com/security/computer_security/editorials/codetools/

Trust: 2.0

url:http://www.securityfocus.com/bid/21960

Trust: 1.7

url:http://osvdb.org/35967

Trust: 1.7

url:http://securitytracker.com/id?1017481

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/31363

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-0201

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-0201

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/31363

Trust: 0.6

url:http://www.fwtk.org

Trust: 0.3

sources: VULHUB: VHN-23563 // BID: 21960 // JVNDB: JVNDB-2007-004934 // CNNVD: CNNVD-200701-138 // NVD: CVE-2007-0201

CREDITS

The vendor disclosed this issue.

Trust: 0.9

sources: BID: 21960 // CNNVD: CNNVD-200701-138

SOURCES

db:VULHUBid:VHN-23563
db:BIDid:21960
db:JVNDBid:JVNDB-2007-004934
db:CNNVDid:CNNVD-200701-138
db:NVDid:CVE-2007-0201

LAST UPDATE DATE

2025-04-10T23:22:33.697000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-23563date:2017-07-29T00:00:00
db:BIDid:21960date:2007-01-10T17:20:00
db:JVNDBid:JVNDB-2007-004934date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200701-138date:2007-01-14T00:00:00
db:NVDid:CVE-2007-0201date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-23563date:2007-01-11T00:00:00
db:BIDid:21960date:2007-01-09T00:00:00
db:JVNDBid:JVNDB-2007-004934date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200701-138date:2007-01-11T00:00:00
db:NVDid:CVE-2007-0201date:2007-01-11T11:28:00