PT-2006-7165 · Proftpd · Proftpd
Revenge
·
Published
2006-12-15
·
Updated
2018-10-17
·
CVE-2006-6563
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.1rc1
Description
The issue is a stack-based buffer overflow in the
pr ctrls recv request function, located in the ctrls.c file of the mod ctrls module. This allows local users to execute arbitrary code by providing a large reqarglen length value.Recommendations
For versions prior to 1.3.1rc1, update to version 1.3.1rc1 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proftpd