Release date: 2011-11-14
Updated on: 2011-11-15
Affected Systems:
VanDyke Software AbsoluteFTP 2.x
Description:
--------------------------------------------------------------------------------
AbsoluteFTP is an FTP File Transfer tool of VanDyke Software. It has the functions of Automatic File Transfer and site synchronization.
AbsoluteFTP has a security vulnerability when processing file names in the directory LIST. You can use a special ftp list command to respond to this vulnerability, causing stack buffer overflow and arbitrary code execution.
<* Source: Node
Link: http://www.exploit-db.com/exploits/18102/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VanDyke Software
----------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.vandyke.com/products/