PT-2004-1500 · Proftpd · Proftpd

Published

2004-03-18

·

Updated

2024-02-02

·

CVE-2004-0346

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProFTPD versions 1.2.7 through 1.2.9rc2
Description The issue is caused by an off-by-one buffer overflow in the xlate ascii write() function. This can be exploited by a remote attacker who issues a specially crafted RETR command containing 1023 bytes or more that begins with a Line Feed (LF) character, allowing the attacker to overflow a buffer and execute arbitrary code on the system with the privileges of ProFTPD.
Recommendations For ProFTPD versions 1.2.7 through 1.2.9rc2, update to version 1.2.9rc3 or later to resolve the issue. As a temporary workaround, consider restricting access to the RETR command until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2004-0346

Affected Products

Proftpd