CVE-2006-6563: Buffer Overflow
Stack-based buffer overflow in the prctrlsrecvrequest function in ctrls.c in the modctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6563?
CVE-2006-6563 has been assigned a medium to high severity rating due to its ability to allow local users to execute arbitrary code.
How do I fix CVE-2006-6563?
To fix CVE-2006-6563, upgrade ProFTPD to version 1.3.1rc1 or later, where the vulnerability has been corrected.
Who is affected by CVE-2006-6563?
CVE-2006-6563 affects local users of ProFTPD versions 1.3.0 and 1.3.0a, who could potentially exploit this vulnerability.
What type of vulnerability is CVE-2006-6563?
CVE-2006-6563 is a stack-based buffer overflow vulnerability, which can lead to arbitrary code execution.
Is CVE-2006-6563 exploitable remotely?
CVE-2006-6563 is not directly exploitable remotely as it requires local user access to trigger the stack-based buffer overflow.