First published: Thu May 04 2006(Updated: )
Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the MLSD command, or (2) the remote server interface, as demonstrated by the Infigo FTPStress Fuzzer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla VPN |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2173 is considered a critical vulnerability as it allows for denial of service and potential remote code execution.
To fix CVE-2006-2173, upgrade to the latest version of FileZilla Server that addresses this buffer overflow vulnerability.
CVE-2006-2173 affects FileZilla FTP Server version 2.2.22 and possibly earlier versions.
CVE-2006-2173 can be exploited by remote authenticated attackers to launch denial of service attacks or execute arbitrary code.
Yes, CVE-2006-2173 has been demonstrated to be exploitable using tools like the Infigo FTPStress Fuzzer.