FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
BID:50412
Info
FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 50412 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3991 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2011 12:00AM |
| Updated: | Oct 28 2011 12:00AM |
| Credit: | Makoto Shiotsuki |
| Vulnerable: |
FFFTP FFFTP 1.98a FFFTP FFFTP 1.96b |
| Not Vulnerable: |
FFFTP FFFTP 1.98b |
Discussion
FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
FFFTP is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute an arbitrary program in the context of the user running the affected application.
FFFTP versions prior to 1.98b are vulnerable.
FFFTP is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute an arbitrary program in the context of the user running the affected application.
FFFTP versions prior to 1.98b are vulnerable.
Exploit / POC
FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
Attackers must entice an unsuspecting user into opening a file on a remote WebDAV or SMB share to exploit this issue.
Attackers must entice an unsuspecting user into opening a file on a remote WebDAV or SMB share to exploit this issue.
Solution / Fix
FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
FFFTP Insecure Excutable File Loading Arbitrary Code Execution Vulnerability
References:
References:
- FFFTP Homepage (FFFTP)
- FFFTP may insecurely load executable files (JPCERT/CC and IPA)
- Information security vulnerabilities / about FFFTP (FFFTP)
- Run the file read vulnerability in FFFTP (IPA)