Summary
This host is installed with Attachmate Reflection FTP Client and is prone to buffer overflow vulnerability.
Impact
Successful exploitation will allow attacker to execution of arbitrary code.
Impact Level: Application
Solution
Upgrade to the latest version or apply the fix,
For updates refer to http://support.attachmate.com/techdocs/1708.html
*****
NOTE : Ignore this warning, if above mentioned patch is applied already.
*****
Insight
The flaw is due to boundary error in the Reflection FTP client in rftpcom.dll, which fails to process filenames within a directory listing.
Affected
Attachmate Reflection 2008
Attachmate Reflection 2011 R1 before 15.3.2.569
Attachmate Reflection 2011 R2 before 15.4.1.327
Attachmate Reflection 14.1 SP1 before 14.1.1.206
Attachmate Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186
References
- http://osvdb.org/77189
- http://secunia.com/advisories/46879
- http://support.attachmate.com/techdocs/1708.html
- http://support.attachmate.com/techdocs/2288.html
- http://support.attachmate.com/techdocs/2502.html
- http://www.exploit-db.com/exploits/18119/
- http://www.securitytracker.com/id?1026340
- http://xforce.iss.net/xforce/xfdb/71330
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2011-5012 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities