PT-2014-3702 · Attachmate · Attachmate Reflection Ftp Client

Rgod

·

Published

2014-08-12

·

Updated

2015-02-09

·

CVE-2014-0603

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Attachmate Reflection FTP Client versions prior to 14.1.429
Description The issue allows remote attackers to cause a denial of service and execute arbitrary code via vectors related to the GetGlobalSettings or GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory address.
Recommendations For versions prior to 14.1.429, update to version 14.1.429 or later to resolve the issue. As a temporary workaround, consider disabling the GetGlobalSettings and GetSiteProperties3 methods until a patch is available. Restrict access to the rftpcom.dll ActiveX control to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0603
ZDI-14-288
ZDI-14-291

Affected Products

Attachmate Reflection Ftp Client