Buffer Overrun Vulnerability in CuteFTP for Windows
A buffer-overflow vulnerability in CuteFTP 5.0 XP for Windows can permit an attacker to execute arbitrary code on the vulnerable system.
January 20, 2003
Reported January 18, 2003, byLance Fitz-Herbert.
VERSIONS AFFECTED
GlobalSCAPE CuteFTP 5.0 XP for Windows, build 50.6.10.2
DESCRIPTION
Abuffer-overflow vulnerability in CuteFTP 5.0 XP for Windows can permit anattacker to execute arbitrary code on the vulnerable system. When an FTP serverresponds to a List command (i.e., to obtain a directory listing), the responsetravels over a data connection. Sending 257 bytes over a data connection causesa buffer overflow, so the attacker can completely overwrite the IP register bysending 260 bytes of data.
VENDOR RESPONSE
GlobalSCAPEhas been notified but hasn't yet released a fix or workaround for thisvulnerability.
CREDIT
Discoveredby Lance Fitz-Herbert.
About the Author
You May Also Like