CVE-2019-25614
CRIT 9.8Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.
Affected Applications in Environment
1
server
v1.0.0.0
1 device
Affected Devices
1
EBB107-01
Windows