vendor:
Golden FTP Server
by:
1F98D
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Golden FTP Server
Affected Version From: 4.7
Affected Version To: 4.7
Patch Exists: NO
Related CWE:
CPE: a:goldenftp:golden_ftp_server:4.70
Platforms Tested: Windows 10 (x64)
Golden FTP Server 4.70 – ‘PASS’ Buffer Overflow (2)
A buffer overflow exists in GoldenFTP during the authentication process. Note that the source ip address of the user performing the authentication forms part of the buffer and as such must be accounted for when calculating the appropriate offset. It should also be noted that the exploit is rather unstable and if exploitation fails, GoldenFTP will be left in a state where it will still accept connections, but it will be unable to handle or process them in anyway, so be careful.
Mitigation:
Update to a patched version of Golden FTP Server.