20040228 Critical WFTPD buffer overflow vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=107801208004699&w=2 CVE-2004-0340
WFTPD Server 3.21 - Remote Buffer Overflow
Record summary
CVE-2004-0340 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWFTPD Server 3.21 - Remote Buffer OverflowExploitDB exploitby rdxaxlNot analyzed1 file
References
511001Third-party advisory
http://secunia.com/advisories/11001 9767vdb entry
http://www.securityfocus.com/bid/9767 wftpd-ftp-commands-bo(15340)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15340 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0340