Description
Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields, causing the application to crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Ivan Marmolejo
References
www.exploit-db.com/exploits/48262 (ExploitDB-48262)
tr.oldversion.com/windows/odin-secure-ftp-expert-7-6-3 (Archived Software Download)
www.vulncheck.com/...-ftp-expert-site-info-denial-of-service (VulnCheck Advisory: Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service)