ProFTP 2.9 Client Banner Buffer Overflow

Strike ID:
D09-62g01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2009

Description

This strike exploits a buffer overflow vulnerability in ProFTP client 2.9. The vulnerability is due to failure to sanitize input when view an FTP server welcome message. By enticing a user to view a crafted FTP welcome message, an attacker could remotely execute arbitrary code.

CVE

Bid