Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2012-09-15T17:00:00

Updated: 2024-08-07T00:30:46.804Z

Reserved: 2012-09-15T00:00:00

Link: CVE-2011-5166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-09-15T17:55:04.753

Modified: 2017-08-29T01:30:42.803

Link: CVE-2011-5166

cve-icon Redhat

No data.