FTPPad <= 1.2.0 Stack Buffer Overflow
Vulnerability Description
FTPPad <= 1.2.0 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long directory and filename, the application fails to properly validate input length. This results in a buffer overflow that overwrites the saved Extended Instruction Pointer (EIP), allowing remote attackers to execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-20108
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- corelanc0d3r of Corelan Team
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/ftppad_list_reply.rb
- https://www.exploit-db.com/exploits/16726
- https://web.archive.org/web/20111016194057/https://www.corelan.be/index.php/2010/10/12/death-of-an-ftp-client/
- https://www.chip.de/downloads/FTPPad_12993921.html
- https://www.vulncheck.com/advisories/ftppad-stack-buffer-overflow
Affected Vendor
FTPPad
View all reports →