CVE-2010-4221
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.
- Affected products
- Proftpd
- Proftpd
- = 1.3.2, 1.3.3
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 91.3% (100th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2010-11-09
CVE-2010-4221 at NVD
12 known exploits for CVE-2010-4221
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2010-4221
MACHINE-BASIC-PENTESTING-1
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (FreeBSD)
ProFTPD Telnet IAC buffer overflow
ProFTPD Telnet IAC buffer overflow
ProFTPD Telnet IAC buffer overflow
ProFTPD Telnet IAC buffer overflow
ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)
ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)
ProFTPd IAC 1.3.x - Remote Command Execution
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (Linux)
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (FreeBSD)