vendor:
PyroBatchFTP
by:
Manuel García Cárdenas
N/A
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: PyroBatchFTP
Affected Version From: PyroBatchFTP <= 3.18
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows
2018
MGC ALERT 2018-001
The Enterprise version of PyroBatchFTP is affected by a Local Buffer Overflow vulnerability. The application does not check bounds when reading the file that will execute the script, resulting in a classic Buffer Overflow overwriting SEH handler. To exploit the vulnerability, only a local script is needed to interact with the application.
Mitigation:
Vendor release 3.19 version