vendor:
glFTPd
by:
CoKi
7.5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: glFTPd
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Slackware 9.0, 9.1, and 10.0
2004
glFTPd local stack buffer overflow exploit
This is a proof of concept exploit for a local stack buffer overflow vulnerability in glFTPd. The exploit has been tested on Slackware 9.0, 9.1, and 10.0. It allows an attacker to execute arbitrary code with the privileges of the glFTPd process.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. In the meantime, users should consider disabling or restricting access to the vulnerable function.