vendor:
FreeFTPd
by:
riaf [at] mysec.org
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FreeFTPd
Affected Version From: 1.0.10
Affected Version To: 1.0.10
Patch Exists: NO
Related CWE: CVE-2006-2407
CPE: a:freeftpd:freeftpd:1.0.10
Platforms Tested: Windows
2006
FreeFTPd 1.0.10 Key Exchange Algorithm String Buffer Overflow
This module exploits a simple stack buffer overflow in FreeFTPd 1.0.10. This flaw is due to a buffer overflow error when handling a specially crafted key exchange algorithm string received from an SSH client. This module is based on MC's freesshd_key_exchange exploit.
Mitigation:
Apply the vendor patch or upgrade to a newer version of FreeFTPd.