Description
FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to execute arbitrary code. Attackers can craft a malicious preference file with carefully constructed shellcode to trigger a structured exception handler overwrite and execute system commands.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Felipe Winsnes
References
www.exploit-db.com/exploits/48685 (ExploitDB-48685)
www.dummysoftware.com/ftpdummy.html (Official FTPDummy Software Homepage)
www.vulncheck.com/advisories/ftpdummy-local-buffer-overflow (VulnCheck Advisory: FTPDummy 4.80 - Local Buffer Overflow)