PT-2003-1713 · Igloo · Iglooftp Pro
Peter Winter-Smith
·
Published
2003-07-15
·
Updated
2016-10-18
·
CVE-2003-0561
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
IglooFTP PRO version 3.8
Description:
The issue is related to multiple buffer overflows that can be triggered by remote FTP servers. This can occur through a long FTP banner or long responses to certain client commands, including
USER, PASS, and ACCT, potentially allowing remote FTP servers to execute arbitrary code.Recommendations:
For IglooFTP PRO version 3.8, consider disabling the FTP client functionality until a patch is available to prevent potential exploitation. Restrict access to the FTP server to minimize the risk of arbitrary code execution. Avoid using the
USER, PASS, and ACCT commands in the affected version until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iglooftp Pro