PT-2026-26999 · Skyqinsc · Miniftpd
Strider
·
Published
2026-03-22
·
Updated
2026-03-22
·
CVE-2019-25611
CVSS v3.1
8.4
High
| AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
MiniFtp contains a buffer overflow vulnerability in the parseconf load setting function that allows local attackers to execute arbitrary code by supplying oversized configuration values. Attackers can craft a miniftpd.conf file with values exceeding 128 bytes to overflow stack buffers and overwrite the return address, enabling code execution with root privileges.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Miniftpd