Buffer Overrun Vulnerability in CuteFTP for Windows

A buffer-overflow vulnerability in CuteFTP 5.0 XP for Windows can permit an attacker to execute arbitrary code on the vulnerable system.

Ken Pfeil

January 20, 2003

1 Min Read
ITPro Today logo

Reported January 18, 2003, byLance Fitz-Herbert.

 

 

VERSIONS AFFECTED

 

  • GlobalSCAPE CuteFTP 5.0 XP for Windows, build 50.6.10.2

 

 

DESCRIPTION

 

Abuffer-overflow vulnerability in CuteFTP 5.0 XP for Windows can permit anattacker to execute arbitrary code on the vulnerable system. When an FTP serverresponds to a List command (i.e., to obtain a directory listing), the responsetravels over a data connection. Sending 257 bytes over a data connection causesa buffer overflow, so the attacker can completely overwrite the IP register bysending 260 bytes of data.

 

VENDOR RESPONSE

 

GlobalSCAPEhas been notified but hasn't yet released a fix or workaround for thisvulnerability.

 

CREDIT

Discoveredby Lance Fitz-Herbert.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like