vendor:
SmartFTP Client
by:
Marsu
7.5
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: SmartFTP Client
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SmartFTP Client v 2.0.1002 Heap Overflow DoS
There is a remote heap overflow in SmartFTP. When the app receives a long banner (5000 char), the heap is smashed, leading to DoS and code execution. There are also two buffer overflows in the fields Address and Login. Reported to Secunia but not published. A simple drag'n drop could compromise the system.
Mitigation:
Unknown