Description
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
Problem types
Product status
Credits
Chase Hatch (SYANiDE)
References
www.exploit-db.com/exploits/47576 (ExploitDB-47576)
ayukov.com/nftp/ (Vendor Homepage)
www.vulncheck.com/...ayukov-nftp-client-syst-buffer-overflow (VulnCheck Advisory: Ayukov NFTP client 1.71 - 'SYST' Buffer Overflow)