CVE-2009-0351: Buffer Overflow
Published Jan 29, 2009
·Updated
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an (asterisk) character.
Affected Software
1 affected component
Wftpserver Winftp Ftp Server=2.3.0
Event History
Jan 29, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0351?
CVE-2009-0351 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2009-0351?
To fix CVE-2009-0351, upgrade to a version of WinFTP that is not affected by this vulnerability.
3
Who is affected by CVE-2009-0351?
Users of WinFTP server version 2.3.0 are specifically affected by CVE-2009-0351.
4
What type of attack is associated with CVE-2009-0351?
CVE-2009-0351 is associated with stack-based buffer overflow attacks initiated through malicious LIST commands.
5
Can CVE-2009-0351 be exploited remotely?
Yes, CVE-2009-0351 can be exploited remotely by authenticated users exploiting the vulnerable LIST functionality.