Overview

Introduction

Welcome to the homepage of FileZilla, the free FTP solution. Both a client and a server are available. FileZilla is open source software distributed under the terms of the GNU General Public License

Support is available through our forums, the wiki and the bug and feature request trackers.

In addition, you will find documentation on how to compile FileZilla and nightly builds for multiple platforms in the development section.

Quick download links


News Atom feed icon

2008-08-11 - FileZilla Client 3.1.1.1 released

Bugfixes and minor changes:

  • Fix crash if a connection attempt gets aborted

2008-08-10 - FileZilla Client 3.1.1 released

New features:

  • Save filter toggle state
  • MSW: Display drive labels if available

Bugfixes and minor changes:

  • Fix crash in new socket class if using active mode FTP
  • Request user attention (e.g. blinking in taskbar) if an edited file changes and the program is minimized
  • Don't issue mdtm command on links for the automatic timezone detection on SFTP servers
  • Do not capture menu shortcut keys in file lists
  • Allow directory comparison if filters are toggled off
  • MSW: Sorting in site dropdown menu is now identical to sorting inside the Site Manager
  • OS X: If closing the file rename edit box, refresh neighboring lines to get rid of artifacts left behind by the edit control border

2008-08-04 - FileZilla Client 3.1.1-rc1 released

New features:

  • If using "Ask for password" and "Interactive" logon types, a username is now optional in the Site Manager
  • New iconset: OpenCrystal
  • MSW: Whether icon sets should be installed or not can be seleted in the installer

Bugfixes and minor changes:

  • Fix parsing of URLs containing port number in quickconnect bar
  • Fix handling of local write errors if downloading files
  • If closing FileZilla, the queue is now properly saved using a backup copy to prevent corruption of queue file
  • Slight performance improvement if opening settings dialog, language and theme pages are now populated on demand
  • Reply to server's shutdown notification on SSL/TLS secured downloads if connection still open
  • After downloading files, local file count did not update
  • "My Sites" in Site Manager should not be draggable
  • Fix entering IPv6 addresses in Site Manager
  • Directory cache was incoherent after renaming a directory
  • Several fixes to new socket class
  • MSW: Starting a bounding box selection (Windows calls it marquee selection) did not set focus to the file lists

2008-07-24 - Security Advisory

FileZilla 3.1.0.1 fixes a vulnerability regarding the way some errors are handled on SSL/TLS secured data transfers.

If the data connection of a transfer gets closed, FileZilla did not check if the server performed an orderly TLS shutdown.

Impact

An attacker could send spoofed FIN packets to the client. Even though GnuTLS detects this with GNUTLS_E_UNEXPECTED_PACKET_LENGTH, FileZilla did not record a transfer failure in all cases.

Unfortunately not all servers perform an orderly SSL/TLS shutdown. Since this cannot be distinguished from an attack, FileZilla will not be able to download listings or files from such servers.

Affected versions

All versions prior to 3.1.0.1 are affected. This vulnerability has been fixed in 3.1.0.1