FTP Desktop 3.5 - Banner Parsing Buffer Overflow

EDB-ID:

23117




Platform:

Windows

Date:

2003-09-08


source: https://www.securityfocus.com/bid/8559/info

A buffer overflow vulnerability has been reported in FTP Desktop. The vulnerability occurs when FTP Desktop is parsing 'Welcome' banner 220 messages from remote FTP servers. When FTP Desktop receives an FTP banner exceeding a certain length, it will trigger the overflow condition. This could allow for execution of malicious code in the context of the affected FTP client. 

(FTP Desktop connected...)
PADDING EBP EIP
220 [229xA][4xB][4xX]
(Access violation when executing 0x58585858) // 4xX