vendor:
BPFTP Client Software
by:
Vulnerability Laboratory Researcher
N/A
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: BPFTP Client Software
Affected Version From: 2010.75.0.76
Affected Version To: 2011.x
Patch Exists: NO
Related CWE:
CPE: BPFTP Client Software (Windows)
Platforms Tested: Windows
2012
BulletProof FTP Client 2010 – Buffer Overflow Vulnerability
A Buffer Overflow vulnerability is detected on BulletProof FTP Client v2010.75.0.76. The vulnerability is located in the main executeable bpftpclient.exe. During the start of the application the value LogFileName from the registry key [HKEY_CURRENT_USER/Software/BulletProof Software/BulletProof FTP Client 2010/Options] is read. When inserting an oversized value to the registry value a buffer overflow is triggered. The victim only needs to start the application.
Mitigation:
Unknown