vendor:
ALFTP
by:
Gokul Babu
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ALFTP
Affected Version From: 5.31
Affected Version To: 5.31
Patch Exists: Yes
Related CWE: N/A
CPE: a:altools:alftp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP Professional SP3 -Version-2002
2010
ALFTP 5.31 – Local Buffer Overflow (SEH Bypass)
A local buffer overflow vulnerability exists in ALFTP 5.31. By supplying a maliciously crafted input, an attacker can overwrite the SEH handler and execute arbitrary code. The vulnerability can be exploited by pasting the contents of alftp.txt in 'options->Preference->Security->New password &Confirm password'
Mitigation:
Upgrade to the latest version of ALFTP 5.31 or later.