#VU24401 Buffer overflow in uftpd - CVE-2020-5204
Published: January 20, 2020
uftpd
Joachim Nilsson
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in "handle_PORT" in "ftpcmd.c" file when a buffer that is 16 bytes large being filled via "sprintf()" with user input based on the format specifier string %d.%d.%d.%d. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.