A remote overflow exists in Xlight FTP server. The Xlight FTP server fails to properly check boundries on FTP arguments resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code or application failure resulting in a loss of confidentiality, integrity, and/or availability.
Classification
Attack Type:
Input Manipulation
Technical
An attacker can present a PASS command request with a excessively long string to the vulnerable server.
Solution
Upgrade to version 1.45 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.