Vulnerability Description
Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate the length of filenames. A crafted response containing an overly long filename can overwrite the Structured Exception Handler (SEH), potentially allowing remote code execution.
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exp
- https://web.archive.org/web/20111016194057/https://www.corelan.be/index.php/2010
- https://www.exploit-db.com/exploits/16728
- https://www.gekkomanager.com/
- https://www.vulncheck.com/advisories/gekko-manager-ftp-client-stack-buffer-overf
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exp
- https://www.exploit-db.com/exploits/16728
FAQ
What is CVE-2010-20034?
CVE-2010-20034 is a documented vulnerability. Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate ...
How severe is CVE-2010-20034?
CVSS scoring is not yet available for CVE-2010-20034. Check NVD for updates.
Is there a patch for CVE-2010-20034?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.