CVE-2011-5012
Last modified
CVE-2011-5012 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.. EPSS estimates a 7.85% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Attachmate | Reflection | 7.2 | Sp1 |
| Attachmate | Reflection | 14.1 | Sp1 |
| Attachmate | Reflection 2008 | All versions | — |
| Attachmate | Reflection 2008r1 | sp1 | — |
| Attachmate | Reflection 2008r2 | All versions | — |
| Attachmate | Reflection 2011r1 | All versions | — |
References
- http://secunia.com/advisories/46879Vendor Advisory
- http://secunia.com/advisories/46879Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-5012?
How severe is CVE-2011-5012?
How do I fix CVE-2011-5012?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-5006Stack-based buffer overflow in QQPlayer 3.2.845 allows remot…
- CVE-2011-5007Stack-based buffer overflow in the CmpWebServer component in…
- CVE-2011-5008Integer overflow in the GatewayService component in 3S CoDeS…
- CVE-2011-5009The CmpWebServer.dll module in the Control service in 3S CoD…
- CVE-2011-5010apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 …
- CVE-2011-5011Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2011-5018Koala Framework before 2011-11-21 has XSS via the request_ur…6.1
- CVE-2011-5019Cross-site scripting (XSS) vulnerability in setup/index.php …
- CVE-2011-5020An SQL Injection vulnerability exists in the ID parameter in…9.8
- CVE-2011-5021PHPIDS before 0.7 does not properly implement Regular Expres…
- CVE-2011-5022SQL injection vulnerability in search.php in Pligg CMS 1.1.2…
- CVE-2011-5023Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 …
Are you affected by CVE-2011-5012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
