CVE-2020-20276

CRITICAL

Troglobit Uftpd < 2.10 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://arinerron.com/blog/posts/6

Scores

CVSS v3 9.8
EPSS 0.0460
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
troglobit/uftpd < 2.10
Published Dec 18, 2020
Tracked Since Feb 18, 2026