Summary
This host is installed with ALFTP and is prone to insecure executable file loading vulnerability.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code.
Impact Level: System/Application
Solution
Upgrade to the ALFTP version 5.31 or later,
For updates refer to http://www.altools.jp/download/ALFTP.aspx
Insight
The flaw is due to the application loading executables (readme.exe) in an insecure manner. This can be exploited to run an arbitrary program by tricking a user into opening a file located on a remote WebDAV or SMB share.
Affected
ALFTP version prior to 5.31
References
Severity
Classification
-
CVE CVE-2012-0315 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe AIR Multiple Vulnerabilities -01 April 13 (Mac OS X)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Mac OS X)
- Adobe Acrobat and Reader Multiple Vulnerabilities -July10 (Windows)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Windows)
- Adobe AIR Code Execution and DoS Vulnerabilities Nov13 (Mac OS X)