vendor:
zFTP Client
by:
Juan Sacco
8,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: zFTP Client
Affected Version From: 20061220+dfsg3-4.1
Affected Version To: 20061220+dfsg3-4.1
Patch Exists: YES
Related CWE: N/A
CPE: a:cernlib:zftp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0 x86
2020
zFTP Client – Local Buffer Overflow by Juan Sacco
This exploit is a local buffer overflow vulnerability in zFTP Client. It was developed using Exploit Pack v5.4 by Juan Sacco. The vulnerable code is located in Line 30 of strcpy_chk.c. The affected version is 20061220+dfsg3-4.1. The exploit was tested and developed under Kali Linux 2.0 x86. The Kali Linux 2.0 package is pool/main/c/cernlib/zftp_20061220+dfsg3-4.1_i386.deb with MD5sum 524217187d28e4444d6c437ddd37e4de. The exploit uses a NOPSLED, shellcode and EIP to execute the attack.
Mitigation:
The user should update to the latest version of zFTP Client.