CVE-2005-3684: Buffer Overflow
Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3684?
CVE-2005-3684 is classified as a high severity vulnerability due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2005-3684?
To fix CVE-2005-3684, upgrade to a patched version of freeFTPd that addresses the buffer overflow vulnerabilities.
Can CVE-2005-3684 be exploited remotely?
Yes, CVE-2005-3684 can be exploited remotely by authenticated attackers via specially crafted MKD and DELE commands.
What are the potential impacts of CVE-2005-3684?
The impacts of CVE-2005-3684 include application crashes and possible execution of arbitrary code on the affected system.
Is logging a factor in CVE-2005-3684?
Yes, CVE-2005-3684 affects versions of freeFTPd without logging enabled, which may impact incident detection.