1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




FileZilla SSL/TLS Secure Data Transfer Vulnerability

Report ID: SA200906330
Source: F-Secure
Date of Discovery: 17.12.2009
Criticality: Low
Affects:
FileZilla Client 2.x
FileZilla Client 3.x

 

Compromise From: From local network
Compromise Type: Security bypass

Summary

A vulnerability has been reported in the file transfer client FileZilla that if exploited, can allow a local attacker to bypass native security mechanisms on the system.

Detailed Description

The vulnerability reolves around improper handling of errors in SSL/TLS secure data transfers. If a transfer data connection is closed, FileZilla does not check to confirm a proper TLS shutdown. This may result in transfer failures, and may be exploited by an attacker using spoofed FIN packets sent to the client.

Solution

Upgrade to version 3.0.10 or later

  • FileZilla latest versions
    http://filezilla-project.org/versions.php

Original Reference

-