CVE Vulnerabilities

CVE-2006-6170

Published: Nov 30, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815.

Affected Software

NameVendorStart VersionEnd Version
ProftpdProftpd_project*1.3.0a (including)
ProftpdUbuntudapper*
ProftpdUbuntuedgy*
Proftpd-dfsgUbuntudevel*
Proftpd-dfsgUbuntufeisty*
Proftpd-dfsgUbuntugutsy*
Proftpd-dfsgUbuntuhardy*
Proftpd-dfsgUbuntuintrepid*
Proftpd-dfsgUbuntujaunty*
Proftpd-dfsgUbuntukarmic*

References