Moderately critical vulnerability discovered in Filezilla

Apr 17, 2007 07:33 GMT  ·  By

A new vulnerability was discovered in Filezilla, one of the most popular FTP clients on the Internet used to download and upload files on a server. At this time, the file transfer protocol is used by a lot of Internet customers because it is faster and more stable. That's why a lot of software companies are trying to build FTP clients able to provide the best functionality and attract the majority of users. Filezilla is just one of them, but it managed to become one of the most popular applications because it provides powerful functions bundled with minimum requirements. Because I'm sure that many of you are currently using Filezilla, I must inform you that you really need to update your application as the older version contains a moderately critical flaw. According to security company Secunia, the previous editions of the FTP client have a vulnerability able to allow an attacker to take the control over an affected system.

"Some vulnerabilities have been reported in FileZilla, which potentially can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to various unspecified format string errors. These can potentially be exploited to execute arbitrary code via e.g. specially crafted server responses or data containing format string specifiers sent when a user interacts with a malicious FTP server," Secunia sustained in the advisory.

It seems like the only solution to avoid a successful exploitation of the flaw is to update to the latest version of the program, currently 2.2.32, available as a free download on Softpedia. As you surely know, there are a lot of FTP clients available on the Internet but the security of your computer is threatened by most of them. Let me explain why: every time a user connects to a malicious FTP server, an attacker is able to control the system using a simple downloaded file. So, no matter what FTP client you're using, you're vulnerable and Filezilla can be regarded as an example.