FTP Desktop Banner Parsing Buffer Overflow Vulnerability
BID:8559
Info
FTP Desktop Banner Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 8559 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2003 12:00AM |
| Updated: | Sep 08 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Bahaa Naamneh <[email protected]>. |
| Vulnerable: |
FTP Desktop FTP Desktop 3.5 |
| Not Vulnerable: |
FTP Desktop FTP Desktop 3.5.2 |
Discussion
FTP Desktop Banner Parsing Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported in FTP Desktop. The vulnerability occurs when FTP Desktop is parsing 'Welcome' banner 220 messages from remote FTP servers. When FTP Desktop receives an FTP banner exceeding a certain length, it will trigger the overflow condition. This could allow for execution of malicious code in the context of the affected FTP client.
A buffer overflow vulnerability has been reported in FTP Desktop. The vulnerability occurs when FTP Desktop is parsing 'Welcome' banner 220 messages from remote FTP servers. When FTP Desktop receives an FTP banner exceeding a certain length, it will trigger the overflow condition. This could allow for execution of malicious code in the context of the affected FTP client.
Solution / Fix
FTP Desktop Banner Parsing Buffer Overflow Vulnerability
Solution:
This issue has been addressed in FTP Desktop versions 3.5.2 and later.
FTP Desktop FTP Desktop 3.5
Solution:
This issue has been addressed in FTP Desktop versions 3.5.2 and later.
FTP Desktop FTP Desktop 3.5
-
FTP Desktop FTP Desktop 3.5.2
http://www.ftpdesktop.net/download/ftpsetup.exe
References
FTP Desktop Banner Parsing Buffer Overflow Vulnerability
References:
References:
- FTP Desktop Downloads (FTP Desktop)
- FTP Desktop Homepage (FTP Desktop)