CVE-2010-20007 Details
Description
Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long filename, the application fails to properly validate input length, resulting in a buffer overflow that overwrites the Structured Exception Handler (SEH). This may allow remote attackers to execute arbitrary code on the client system. This product line was discontinued and users were advised to use BlueZone Secure FTP instead, at the time of disclosure.
A stack-based buffer overflow vulnerability has been identified in Seagull FTP Client versions through 3.3 Build 409. The issue arises in the FTP directory listing parser, where the client fails to properly validate the length of filenames in responses to the LIST command. This vulnerability allows remote attackers to overwrite the Structured Exception Handler (SEH), potentially leading to arbitrary code execution on the client system.
Users are advised to switch to BlueZone Secure FTP, as the Seagull FTP Client product line has been discontinued.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 21, 2025CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Seagull FTP Client | All versions |
CPE
Remediation
| |
| Rocket BlueZone Secure FTP | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | New CVE Received | [email protected] |
Volerion