QID 377614
Date Published: 2022-10-06
QID 377614: Filezilla Server Information Disclosure Vulnerability (CVE-2014-0224)
FileZilla is an FTP program for file uploading and downloading to and from your FTP site, server, or host.
CVE-2014--0224: OpenSSL does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to hijack sessions or obtain sensitive information, via a crafted TLS handshake, also known as the "CCS Injection" vulnerability. Affected versions
Filezilla server prior to 0.9.45
QID detection logic
It checks for the vulnerable version from the file FileZilla Server.exe
It may impact the confidentiality and integrity.
Solution
Customers are advised to check for Filezilla 0.9.45 (2014-06-07) for more details
Vendor References
- Filezilla server -
filezilla-project.org/versions.php?type=server
CVEs related to QID 377614
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 0.9.45 (2014-06-07) |
|