CVE-2011-5012
Summary
| CVE | CVE-2011-5012 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-25 01:55:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Attachmate | Reflection | 14.1 | sp1 | All | All |
| Application | Attachmate | Reflection | 7.2 | sp1 | windows_client | All |
| Application | Attachmate | Reflection 2008 | All | All | All | All |
| Application | Attachmate | Reflection 2008r1 | sp1 | All | All | All |
| Application | Attachmate | Reflection 2008r2 | All | All | All | All |
| Application | Attachmate | Reflection 2011r1 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Alerts | af854a3a-2127-422b-91ae-364da2661108 | support.attachmate.com | |
| support.attachmate.com/techdocs/2502.html | af854a3a-2127-422b-91ae-364da2661108 | support.attachmate.com | |
| www.osvdb.org/77189 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Security Alerts | af854a3a-2127-422b-91ae-364da2661108 | support.attachmate.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Attachmate Reflection Buffer Overflow in FTP Client Lets Remote Servers Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Attachmate Reflection FTP Client Heap Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| {PRL} Attachmate Reflection FTP Client Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.protekresearchlab.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.