Stack-based buffer overflow in ProFTPD - CVE-2010-4221

 

Stack-based buffer overflow in ProFTPD - CVE-2010-4221

Published: September 15, 2011 / Updated: June 23, 2025


Vulnerability identifier: #VU111809
CSH Severity: High
CVSS v4.0:
CVE-ID: CVE-2010-4221
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: ProFTPD
Affected software:
ProFTPD

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2010-4221

Install update from vendor's website.

Sources