Overview
AmmSoft's ScriptFTP client is susceptible to a remote buffer overflow vulnerability that is triggered when processing a sufficiently long filename during a FTP LIST command.
Description
AmmSoft's ScriptFTP client can be exploited to execute arbitrary code when processing GETLIST or GETFILE FTP commands. More details can be found at the reporter's blog: Digital Echidna |
Impact
An attacker can setup a malicious FTP server that will exploit the vulnerability to cause a denial-of-service crash or may execute arbitrary code on the client's computer with the permissions of the ScriptFTP client user. |
Solution
We are currently unaware of a practical solution to this problem. |
Workarounds Do not connect to untrusted FTP servers. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Tom Gregory for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | None |
Severity Metric: | 0.71 |
Date Public: | 2011-09-20 |
Date First Published: | 2011-09-20 |
Date Last Updated: | 2011-09-20 17:23 UTC |
Document Revision: | 11 |