CVE-2016-5764
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious server.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- http://community.microfocus.com/microfocus/mainframe_solutions/rumba/w/knowledge_base/28731.rumba-ftp-4-x-security-update.aspx
- http://www.securityfocus.com/bid/93974
- https://www.exploit-db.com/exploits/40651/
- http://community.microfocus.com/microfocus/mainframe_solutions/rumba/w/knowledge_base/28731.rumba-ftp-4-x-security-update.aspx
- http://www.securityfocus.com/bid/93974
- https://www.exploit-db.com/exploits/40651/
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.