CVE
- Id
- 8715
- CVE No.
- CVE-2004-0287
- Status
- Candidate
- Description
- Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
- Phase
- Modified (20050518)
- Votes
- NOOP(5) Armstrong, Christey, Cole, Cox, Wall
- Comments
- Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668