FreeFloat FTP Server Buffer Overflow Vulnerability in PROGRESS Command Handler

Vulnerability

A critical buffer overflow vulnerability has been identified in FreeFloat FTP Server version 1.0. This issue arises from an unknown processing flaw in the PROGRESS Command Handler, allowing remote attackers to manipulate the command and cause a buffer overflow. The vulnerability has been publicly disclosed, and an exploit is available.

Impact

Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary code execution on the affected system. The successful exploitation has been demonstrated to provide a remote shell with the privileges of the vulnerable process.

Reproduction

The vulnerability can be reproduced by sending an excessive amount of data through the 'PROGRESS' command. This overloads the application's buffer, causing it to crash and indicating a buffer overflow condition. The exploitation involves calculating the precise offset needed to overwrite the Extended Instruction Pointer (EIP) and redirect execution to a payload, which can be a reverse shell or similar malicious code.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.