FTP: Malicious Characters In FTP Commands
This signature detects attempts to exploit a remote FTP server. Attacker can send malformed characters as FTP commands. A successful attack can lead to arbitrary remote code execution within the context of the server or denial of service condition.
Extended Description
GlobalSCAPE Secure FTP Server is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable server.
Affected Products
Globalscape secure_ftp_server
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Globalscape
Kmint21_software
7.5
10.0