Korean
<< Back
VID 28193
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The FileZilla FTP Client, according to its version number, has format string vulnerabilities which exist in versions prior to 2.2.32. FileZilla is a free Windows-based application for transferring files between PC and an FTP site. FileZilla FTP Client versions prior to 2.2.32 could allow a remote attacker to execute arbitrary code or cause the application crash, caused by multiple format string vulnerabilities. By causing a victim user to connect to a malicious FTP server, a remote attacker could exploit these vulnerabilities to execute arbitrary code on the victim's system.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://sourceforge.net/project/shownotes.php?release_id=501534

* Platforms Affected:
FileZilla SourceForge project, FileZilla FTP Client versions prior to 2.2.32
Microsoft Windows Any version
Recommendation Upgrade to the latest version of FileZilla Client (2.2.32 or later), available from the SourceForge.net FileZilla Client Project Download Web site at
http://sourceforge.net/project/showfiles.php?group_id=21558
Related URL (CVE)
Related URL 23506 (SecurityFocus)
Related URL 33681 (ISS)