vendor:
Ricoh DC Software DL-10 FTP Server (SR10.exe)
by:
Julien Ahrens
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Ricoh DC Software DL-10 FTP Server (SR10.exe)
Affected Version From: <= 1.1.0.6
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Professional German
2012
Ricoh DC Software DL-10 FTP Server (SR10.exe) <= 1.1.0.6 Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in Ricoh DC Software DL-10 FTP Server (SR10.exe) version <= 1.1.0.6. An attacker can send a maliciously crafted request containing a large amount of data to the FTP server, which can cause the server to crash or allow the attacker to execute arbitrary code. This vulnerability affects both Ricoh DC Software DL-10 FTP Server (SR10.exe) and Capftpd (former SR-10).
Mitigation:
Upgrade to the latest version of Ricoh DC Software DL-10 FTP Server (SR10.exe) or Capftpd (former SR-10).