CVE-2010-4221
09.11.2010, 21:00
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.Enginsight
| Vendor | Product | Version |
|---|---|---|
| proftpd | proftpd | 1.3.2 |
| proftpd | proftpd | 1.3.2:a |
| proftpd | proftpd | 1.3.2:b |
| proftpd | proftpd | 1.3.2:c |
| proftpd | proftpd | 1.3.2:d |
| proftpd | proftpd | 1.3.2:e |
| proftpd | proftpd | 1.3.2:rc3 |
| proftpd | proftpd | 1.3.2:rc4 |
| proftpd | proftpd | 1.3.3 |
| proftpd | proftpd | 1.3.3:a |
| proftpd | proftpd | 1.3.3:b |
| proftpd | proftpd | 1.3.3:rc1 |
| proftpd | proftpd | 1.3.3:rc2 |
| proftpd | proftpd | 1.3.3:rc3 |
| proftpd | proftpd | 1.3.3:rc4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References