CVE-2006-4974: Buffer Overflow
Published Sep 25, 2006
·Updated
Buffer overflow in Ipswitch WSFTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.
Affected Software
1 affected component
Ipswitch Ws Ftp Server=5.08_limited_edition
Event History
Sep 25, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4974?
CVE-2006-4974 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2006-4974?
The best way to fix CVE-2006-4974 is to upgrade Ipswitch WS_FTP Limited Edition to a newer, patched version.
3
What vulnerable software is affected by CVE-2006-4974?
CVE-2006-4974 specifically affects Ipswitch WS_FTP Limited Edition version 5.08.
4
What exploit can be used with CVE-2006-4974?
CVE-2006-4974 can be exploited by sending a long response to a PASV command to trigger the buffer overflow.
5
Is there a workaround for CVE-2006-4974?
A potential workaround for CVE-2006-4974 is to restrict access to the FTP server from untrusted networks.