J-Security Center

Title: EFTP Buffer Overflow Code Execution and Denial of Service Vulnerability

Severity: CRITICAL

Description:

Encrypted FTP (EFTP) is both an FTP client and server application for Windows platforms.

A malicious user with upload permissions to the target host can cause a buffer overflow by uploading a *.lnk file containing a certain value. When an LS command is issued on this directory, the buffer overflow allows the stack to be overwritten as well as the return address, causing code of the attacker's choosing to be executed on the local host with the same level of permissions as the EFTP process.

Alternatively, the attacker could also use this exploit to cause a denial of service by having the exploit code continually execute a command such as querying the floppy drive of the target host.

Affected Products:

  • Cisco iCDN 2.0.0
  • Khamil Landross and Zack Jones EFTP 2.0.7 .337

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.