PT-2007-3651 · Filezilla · Filezilla

Published

2007-04-26

·

Updated

2008-11-13

·

CVE-2007-2318

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FileZilla versions prior to 2.2.32
Description The issue involves multiple format string vulnerabilities that allow remote attackers to execute arbitrary code. This can be achieved through format string specifiers in FTP server responses or data sent by an FTP server.
Recommendations For versions prior to 2.2.32, update to version 2.2.32 or later to resolve the issue. As a temporary workaround, consider restricting access to FTP servers until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2318

Affected Products

Filezilla