Skip to main content

CoreFTP buffer overflow vulnerability

Last Update Date: 27 Mar 2013 Release Date: 22 Mar 2013 4114 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been identified in CoreFTP. A remote user can cause arbitrary code to be executed on the target user's system.

The vulnerability is caused due to a buffer overflow error when parsing long directory names from a malicious FTP server. The LIST, VIEW, commands are vulnerable to a denial of service and the DELE command has been reported to be vulnerable to code execution.


Impact

  • Remote Code Execution

System / Technologies affected

  • CoreFTP 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to CoreFTP 2.2 build 1769 or later.

Vulnerability Identifier


Source


Related Link