CVE-2019-25614
EUVD-2019-1996922.03.2026, 14:16
Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| freefloat | freefloat_ftp_server | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration