CVE-2012-5002
Ricoh DC Software DL-10 <4.5.0.1 - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18658
metasploit
WORKING POC
NORMAL
by Julien Ahrens, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/ricoh_dl_bof.rb
References (5)
Scores
EPSS
0.4988
EPSS Percentile
97.8%
Classification
CWE
CWE-119
Status
draft
Affected Products (2)
ricoh/dl-10
ricoh/sr10_ftp_server
Timeline
Published
Sep 19, 2012
Tracked Since
Feb 18, 2026