الجمعة، 10 يونيو 2011

FileZilla, the free FTP solution.

Overview

Welcome to the homepage of FileZilla, the free FTP solution. Both a client and a server are available. FileZilla is open source software distributed free of charge under the terms of the GNU General Public License
Support is available through our forums, the wiki and the bug and feature request trackers.
In addition, you will find documentation on how to compile FileZilla and nightly builds for multiple platforms in the development section.

Quick download links

Pick the client if you want to transfer files. Get the server if you want to make files available for others.

News Atom feed icon

2011-06-07 - FileZilla Server 0.9.39 released

Bugfixes and minor changes:

  • Do not attempt to display a message box if creating an administration interface binding fails. This freezes the service on some machines.
  • On FTP over TLS connections, the socket address family was not initialized from the underlaying socket
  • Fix a bug in IPv4 address filters and increase their performance

2011-06-05 - FileZilla Server 0.9.38 released

New features:

  • IPv6 support
  • Range, wildcard, regular expression and dot-decimal notation subnet IP address filters have been removed. These filter rules need to be recreated using CIDR notation.

Bugfixes and minor changes:

  • Upon /reload-config, notify all running instances, not just the first found.
  • Report correct physical path of aliases in administration interface
  • Fix reply code on permanent bans, not of 5yz type
  • Increased default size of socket buffers
  • Fix a crash when entering invalid IP filters
  • Fixed a crash when a connection closes
  • Updated to most recent OpenSSL version

2011-05-22 - FileZilla Client 3.5.0 released

Bugfixes and minor changes:

  • Don't create queue.xml anymore if it does not exist
  • MSW: Progress lines in transfer queue now appear in correct position after changing the Windows theme
  • MSW: Work around a bug in Windows where a list controls' scroll position changes without the control being notified in any way
  • Several fixes to build system and environment

2010-01-02 - Subversion repository moved

The address of the subversion repository has changed.
The old address, http(s)://filezilla.svn.sourceforge.net/svnroot/filezilla is no longer valid. The new address is http(s)://svn.filezilla-project.org/svn/
The new repository can be browsed using http://svn.filezilla-project.org/filezilla/.

2009-03-03 - Security advisory

FileZilla Server 0.9.31 fixes a buffer overflow in the SSL/TLS code.
This vulnerability could potentially be used for denial of service attacks.

Affected versions

All versions prior to 0.9.31 are affected. This vulnerability has been fixed in 0.9.31

2008-07-24 - Security Advisory

FileZilla 3.1.0.1 fixes a vulnerability regarding the way some errors are handled on SSL/TLS secured data transfers.
If the data connection of a transfer gets closed, FileZilla did not check if the server performed an orderly TLS shutdown.

Impact

An attacker could send spoofed FIN packets to the client. Even though GnuTLS detects this with GNUTLS_E_UNEXPECTED_PACKET_LENGTH, FileZilla did not record a transfer failure in all cases.
Unfortunately not all servers perform an orderly SSL/TLS shutdown. Since this cannot be distinguished from an attack, FileZilla will not be able to download listings or files from such servers.

Affected versions

All versions prior to 3.1.0.1 are affected. This vulnerability has been fixed in 3.1.0.1

ليست هناك تعليقات:

إرسال تعليق