CVE

Id
3117  
CVE No.
CVE-2001-0296  
Status
Candidate  
Description
Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.  
Phase
Proposed (20010404)  
Votes
ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese | RECAST(1) Prosser | REVIEWING(1) Bishop  
Comments
Frech> XF:wftpd-pro-cwd-bo(6184) | Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one. It looks like Can-2001-0296 may be a continuation of CVE 1999-0950. Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950). Just managed to change the code so it requires more characters to overflow the buffer. I haven"t tested this, but just from the available documentation, these problems look like a continuation of the early one.