Check Point Reference: | CPAI-2014-1833 |
Date Published: | 14 Oct 2014 |
Severity: | Medium |
Last Updated: | Tuesday 14 October, 2014 |
Source: | Attachmate 2501 |
Industry Reference: | CVE-2014-0606 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Attachmate INFOConnect Enterprise 9.2.0.1182 or earlier Attachmate Reflection FTP Client 14.1.420.0 or earlier |
Vulnerability Description | A memory corruption vulnerability has been found in Attachmate Reflection FTP Client. The vulnerability is due to an attempt to dereference user-controllable parameter input. Successful exploitation could lead to remote code execution under the security context of the affected user. |
SmartView Tracker will log the following entries:
Attack Name: Web Client Enforcement Violation.
Attack Information: Attachmate Reflection FTP Client ActiveX GetSiteProperties3 Memory Corruption