This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
Shree Lipi 6.0 Setup Site
Open the Shree Lipi installation folder, locate the Fonts folder, select all font files ( .ttf ), right-click, and select Install for all users . Restart your application. Issue 3: Software Crashes on Windows 10
Right-click the desktop shortcut for Shree Lipi, select Properties , go to the Compatibility tab, and permanently check Run this program as an administrator .
Follow these steps to install Shree Lipi 6.0 on your Windows computer. Step 1: Prepare the Setup Files
: Version 6.0 does not support font embedding in PDF documents. If you need to create PDFs where the fonts are embedded for viewing on other machines, you must upgrade to Shree Lipi 7.0 or higher.
While the latest modern versions, such as Shree-Lipi nxt Plus, have since been released with enhanced Unicode support and compatibility with 64-bit applications, many users still rely on version 6.0 for various reasons—be it legacy compatibility, hardware limitations, or specific project requirements. If you are one of them, this comprehensive guide will walk you through the entire process of setting up Shree Lipi 6.0 on your Windows computer. shree lipi 6.0 setup
: Shree Lipi 6.0 is an older release. While it works on legacy versions of Windows (XP, Vista, 7), modern systems like Windows 10 or 11 may require the latest Shree Lipi nxt version for full stability.
Once the core software is installed, the final and most critical step is adding the "Marathi Phonetic Keyboard" to your system's language bar.
: Older versions typically used a parallel port lock, though later updates transitioned toward USB softdog drivers. Installation & Configuration Steps
Before you begin the installation, it's crucial to ensure your computer meets the necessary system requirements. This will help avoid any compatibility issues during the setup process. Open the Shree Lipi installation folder, locate the
Shree Lipi 6.0 was originally designed for Windows XP and Windows 7. However, it can run on Windows 10 and Windows 11 by utilizing built-in compatibility mode tools and administrator privileges. Step-by-Step Installation Process
The setup for version 6.0 was designed for older Windows environments and requires minimal hardware by modern standards:
Intel Pentium 4 or higher (or equivalent AMD processor). RAM: Minimum 512 MB (1 GB or more recommended).
Windows XP, Windows 7, Windows 8, or Windows 10 (32-bit or 64-bit). Follow these steps to install Shree Lipi 6
Allows you to manually choose specific regional languages and modular fonts to save disk space. Click Install and wait for the progress bar to finish. Step 4: Install Hardware Dongle Drivers
: Shree Lipi 6.0 includes a powerful Exchange Utility that allows for seamless data conversion between different vendors' font formats. You can convert data from formats like ISFOC, Akruti, Akshar, Anu, Kruti, and many more . This is a lifesaver when working with files from various sources.
In the landscape of Indian language computing, by Modular Infotech has held the title of the de facto standard for decades. While newer, cloud-based tools have emerged, the demand for a robust, offline desktop solution remains high. Shree Lipi 6.0 represents a significant milestone in this legacy, bridging the gap between legacy font formats and modern Windows compatibility.
Avoid downloading files/directories from untrusted FTP servers.
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.