Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

WS_FTP Pro ASCII Directory Transfer Buffer Overflow

Mar 16, 2004 4:34PM PST

Summary
WS_FTP Pro is "the market leader in Windows-based FTP (file transfer protocol) client software". WS_FTP Pro suffers a buffer over-run when ASCII mode directory data is passed to the client from the server, and this data exceeds 260 bytes without a terminating CR/LF.

Details
Vulnerable Systems:
* WS_FTP Pro version 8.02 and prior

Immune Systems:
* WS_FTP Pro version 8.03 or newer

http://www.securiteam.com/windowsntfocus/5PP0C1PCAO.html

Discussion is locked