Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Proftpd | Proftpd_project | 1.3.0 (including) | 1.3.0 (including) |
Proftpd | Proftpd_project | 1.3.0a (including) | 1.3.0a (including) |
Proftpd | Ubuntu | dapper | * |
Proftpd | Ubuntu | edgy | * |
Proftpd-dfsg | Ubuntu | devel | * |
Proftpd-dfsg | Ubuntu | feisty | * |
Proftpd-dfsg | Ubuntu | gutsy | * |
Proftpd-dfsg | Ubuntu | hardy | * |
Proftpd-dfsg | Ubuntu | intrepid | * |
Proftpd-dfsg | Ubuntu | jaunty | * |
Proftpd-dfsg | Ubuntu | karmic | * |