WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of %s sequences, possibly indicating a format string vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
War_ftp_daemon | War_ftp_daemon | 1.8 (including) | 1.8 (including) |
War_ftp_daemon | War_ftp_daemon | 1.82_rc9 (including) | 1.82_rc9 (including) |