Lucene search

K
cveMitreCVE-2011-5012
HistoryDec 25, 2011 - 1:55 a.m.

CVE-2011-5012

2011-12-2501:55:05
CWE-119
mitre
web.nvd.nist.gov
29
cve-2011-5012
heap-based buffer overflow
reflection ftp client
remote code execution
nvd
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.022

Percentile

89.6%

Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.

Affected configurations

Nvd
Node
attachmatereflectionMatch7.2sp1windows_client
OR
attachmatereflectionMatch14.1sp1
OR
attachmatereflection_2008
OR
attachmatereflection_2008r1Matchsp1
OR
attachmatereflection_2008r2
OR
attachmatereflection_2011r1
VendorProductVersionCPE
attachmatereflection7.2cpe:2.3:a:attachmate:reflection:7.2:sp1:windows_client:*:*:*:*:*
attachmatereflection14.1cpe:2.3:a:attachmate:reflection:14.1:sp1:*:*:*:*:*:*
attachmatereflection_2008*cpe:2.3:a:attachmate:reflection_2008:*:*:*:*:*:*:*:*
attachmatereflection_2008r1sp1cpe:2.3:a:attachmate:reflection_2008r1:sp1:*:*:*:*:*:*:*
attachmatereflection_2008r2*cpe:2.3:a:attachmate:reflection_2008r2:*:*:*:*:*:*:*:*
attachmatereflection_2011r1*cpe:2.3:a:attachmate:reflection_2011r1:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.022

Percentile

89.6%

Related for CVE-2011-5012