Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.
2010-11-09T21:00:06.383
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.2 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |
| Application | proftpd | proftpd | 1.3.3 | Yes |