PT-2006-7165 · Proftpd · Proftpd
Revenge
·
Publicado
2006-12-15
·
Atualizado
2018-10-17
·
CVE-2006-6563
CVSS v2.0
6.6
Média
| Vetor | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.1rc1
Description
The issue is a stack-based buffer overflow in the
pr ctrls recv request function, located in the ctrls.c file of the mod ctrls module. This allows local users to execute arbitrary code by providing a large reqarglen length value.Recommendations
For versions prior to 1.3.1rc1, update to version 1.3.1rc1 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Proftpd