Overview
AmmSoft's ScriptFTP client is susceptible to a remote buffer overflow vulnerability that is triggered when processing a sufficiently long filename during a FTP LIST command.
Description
AmmSoft's ScriptFTP client can be exploited to execute arbitrary code when processing GETLIST or GETFILE FTP commands. More details can be found at the reporter's blog: Digital Echidna |
Impact
An attacker can setup a malicious FTP server that will exploit the vulnerability to cause a denial-of-service crash or may execute arbitrary code on the client's computer with the permissions of the ScriptFTP client user. |
Solution
We are currently unaware of a practical solution to this problem. |
Workarounds Do not connect to untrusted FTP servers. |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Thanks to Tom Gregory for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
| CVE IDs: | None |
| Severity Metric: | 0.71 |
| Date Public: | 2011-09-20 |
| Date First Published: | 2011-09-20 |
| Date Last Updated: | 2011-09-20 17:23 UTC |
| Document Revision: | 11 |