Gekko Manager FTP Client <= 0.77 Stack Buffer Overflow
Vulnerability Description
Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate the length of filenames. A crafted response containing an overly long filename can overwrite the Structured Exception Handler (SEH), potentially allowing remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-20034
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- nullthreat
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/gekkomgr_list_reply.rb
- https://www.exploit-db.com/exploits/16728
- https://www.gekkomanager.com/
- https://web.archive.org/web/20111016194057/https://www.corelan.be/index.php/2010/10/12/death-of-an-ftp-client/
- https://www.vulncheck.com/advisories/gekko-manager-ftp-client-stack-buffer-overflow
Affected Vendor
New Software S.C.
View all reports →