FileZilla SSL/TLS Secure Data Transfer Vulnerability
Report ID:
SA200906330
Source:
F-Secure
Date of Discovery:
17.12.2009
Criticality:
Low
Affects:
FileZilla Client 2.x
FileZilla Client 3.x
Compromise From:
From local network
Compromise Type:
Security bypass
Summary
A vulnerability has been reported in the file transfer client FileZilla that if exploited, can allow a local attacker to bypass native security mechanisms on the system.
Detailed Description
The vulnerability reolves around improper handling of errors in SSL/TLS secure data transfers. If a transfer data connection is closed, FileZilla does not check to confirm a proper TLS shutdown. This may result in transfer failures, and may be exploited by an attacker using spoofed FIN packets sent to the client.