Release date: 2012-03-01
Updated on:
Affected Systems:
FlashFXP 4.1.8.1701
Description:
--------------------------------------------------------------------------------
FlashFXP is a popular FTP client.
FlashFXP v4.1.8.1701 the length check is missing when a fixed-length buffer is used in the TListBox control. There is a buffer overflow vulnerability in implementation, which can lead to process control, arbitrary code execution, and system control.
<* Source: Benjamin Kunz Mejri
Link: http://marc.info /? L = full-disclosure & m = 133062892621316 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FlashFXP
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.flashfxp.com/