vendor:
Free Float FTP
by:
Kevin Randall
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: Free Float FTP
Affected Version From: Free Float FTP 1.0
Affected Version To: Free Float FTP 1.0
Patch Exists: NO
Related CWE:
CPE: a:freefloat:free_float_ftp:1.0
Platforms Tested: Windows XP Professional Service Pack 2
2019
Free Float FTP 1.0 “SIZE” Remote Buffer Overflow
This exploit targets a remote buffer overflow vulnerability in Free Float FTP 1.0. By sending a specially crafted "SIZE" command, an attacker can trigger a buffer overflow and potentially execute arbitrary code on the target system.
Mitigation:
The vendor has not released a patch or mitigation for this vulnerability. It is recommended to discontinue the use of Free Float FTP 1.0 and switch to a more secure FTP server software.