First published: Thu Mar 18 2004(Updated: )
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ProFTPD | >=1.2.7<1.2.9 | |
ProFTPD | =1.2.9 | |
ProFTPD | =1.2.9-rc1 | |
ProFTPD | =1.2.9-rc2 | |
ProFTPD | =1.2.9_rc2 | |
ProFTPD | =1.2.7 | |
ProFTPD | =1.2.9_rc1 | |
ProFTPD | =1.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0346 is considered to have a medium severity due to the potential for privilege escalation by local users.
To mitigate CVE-2004-0346, upgrade ProFTPD to version 1.2.9 or later.
CVE-2004-0346 affects ProFTPD versions 1.2.7 through 1.2.9-rc2.
Local users on systems running vulnerable versions of ProFTPD may exploit CVE-2004-0346 to gain elevated privileges.
CVE-2004-0346 is an off-by-one buffer overflow vulnerability in the _xlate_ascii_write() function.