First published: Thu Apr 26 2007(Updated: )
Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla VPN | <=2.2.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2318 has been assessed to have a high severity due to its potential for remote code execution.
To fix CVE-2007-2318, upgrade to FileZilla version 2.2.32 or later.
CVE-2007-2318 affects FileZilla versions prior to 2.2.32.
CVE-2007-2318 allows remote attackers to execute arbitrary code through format string vulnerabilities.
The main cause of CVE-2007-2318 is improper handling of format string specifiers in FTP server responses.