Back to search
CVE-2010-4221
Published: Nov 9, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.proftpd.org/docs/NEWS-1.3.3c
x_refsource_CONFIRM
FEDORA-2010-17091
vendor-advisory
x_refsource_FEDORA
http://www.zerodayinitiative.com/advisories/ZDI-10-229/
x_refsource_MISC
42217
third-party-advisory
x_refsource_SECUNIA
FEDORA-2010-17098
vendor-advisory
x_refsource_FEDORA
FEDORA-2010-17220
vendor-advisory
x_refsource_FEDORA
ADV-2010-2941
vdb-entry
x_refsource_VUPEN
ADV-2010-2962
vdb-entry
x_refsource_VUPEN
42052
third-party-advisory
x_refsource_SECUNIA
http://bugs.proftpd.org/show_bug.cgi?id=3521
x_refsource_CONFIRM
MDVSA-2010:227
vendor-advisory
x_refsource_MANDRIVA
44562
vdb-entry
x_refsource_BID
ADV-2010-2959
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now