vendor:
IglooFTP PRO
by:
vkhoshain@hotmail.com
7.5
CVSS
HIGH
Buffer Overrun
120
CWE
Product Name: IglooFTP PRO
Affected Version From: 3.8
Affected Version To: 3.8
Patch Exists: YES
Related CWE: N/A
CPE: a:iglooftp:iglooftp_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional Build 2600.x
2002
IglooFTP PRO for Windows Buffer Overrun Vulnerability
IglooFTP PRO for Windows platforms has been reported prone to multiple buffer overrun vulnerabilities. The issue likely presents itself due do a lack of sufficient bounds checking performed on data that is copied into a reserved internal memory buffer. Remote arbitrary code execution has been confirmed. It should be noted that although this vulnerability has been reported to affect IglooFTP PRO version 3.8, other versions might also be affected.
Mitigation:
Perform bounds checking on data that is copied into a reserved internal memory buffer.