CoffeeCup Direct/Free FTP Buffer Overflow Vulnerability
- 0
- Add a Comment
- No Related Post
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: UnpatchedSoftware: CoffeeCup Direct FTP 6.x
CoffeeCup Free FTP 3.xKomrade has reported a vulnerability in the third-party wodFtpDLX ActiveX component included in CoffeeCup Direct and CoffeeCup Free FTP, which can be exploited by malicious people to compromise a user’s system.
For more information:
SA13270The vulnerability has been reported in CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10. Other versions may also be affected.
Solution: A fix is not currently available from CoffeeCup Software.
An updated version (2.3.2.97) of the vulnerable third-party ActiveX component is available. However, installing this may potentially impact functionality.
