The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a 0 character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bftpd | Jesse_smith | * | 2.3 (including) |
Bftpd | Jesse_smith | 1.6 (including) | 1.6 (including) |
Bftpd | Jesse_smith | 1.7 (including) | 1.7 (including) |
Bftpd | Jesse_smith | 1.7.2 (including) | 1.7.2 (including) |
Bftpd | Jesse_smith | 1.8 (including) | 1.8 (including) |
Bftpd | Jesse_smith | 2.0.2 (including) | 2.0.2 (including) |
Bftpd | Jesse_smith | 2.0.3 (including) | 2.0.3 (including) |
Bftpd | Jesse_smith | 2.1 (including) | 2.1 (including) |
Bftpd | Jesse_smith | 2.1.1 (including) | 2.1.1 (including) |
Bftpd | Jesse_smith | 2.1.2 (including) | 2.1.2 (including) |
Bftpd | Jesse_smith | 2.2 (including) | 2.2 (including) |
Bftpd | Jesse_smith | 2.2.1 (including) | 2.2.1 (including) |