Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GuildFTPd 'LIST' Command Heap Overflow Vulnerability

GuildFTPd is prone to a heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input. The vulnerability occurs when handling FTP 'LIST' requests.

Successfully exploiting this issue allows attackers to execute arbitrary code with the privileges of a user running the application. Failed exploit attempts will result in a denial-of-service condition.

GuildFTPd 0.999.8.11 and v0.999.14 are vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus