CVE ID | |
CVSS SCORE | 9.0, AV:N/AC:L/Au:S/C:C/I:C/A:C |
AFFECTED VENDORS |
ProFTPD |
AFFECTED PRODUCTS |
FTP Server |
VULNERABILITY DETAILS |
The specific flaw exists within how the server manages the response pool that is used to send responses from the server to the client. When handling an exceptional condition the application will fail to restore the original response pointer which will allow there to be more than one reference to the response pointer. The next time it is used, a memory corruption can be made to occur which can allow for code execution under the context of the application. |
ADDITIONAL DETAILS |
ProFTPD has issued an update to correct this vulnerability. More details can be found at:
http://bugs.proftpd.org/show_bug.cgi?id=3711 |
DISCLOSURE TIMELINE |
|
CREDIT | Anonymous |