i-Ftp 2.20 Schedule.xml Stack-Based Buffer Overflow
Vulnerability Description
A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placing a specially crafted Schedule.xml file in the i-Ftp application directory, a remote attacker can trigger a buffer overflow during scheduled download parsing, potentially leading to arbitrary code execution or a crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-125114
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- metacom
Affected Vendor
i-Ftp
View all reports →