vsftpd '__tzfile_read()' Function Heap Based Buffer Overflow Vulnerability

vsftpd is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.

Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.

vsftpd 2.3.4 is affected; other versions may also be vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus