Home / vulnerabilities proftpdmodtls.txt
Posted on 01 December 2006
Source : packetstormsecurity.org Link
Name: ProFTPD mod_tls pre-authentication buffer overflow
Vendor: http://www.proftpd.org
Release date: 28 Nov, 2006
Author: Evgeny Legerov <research@gleg.net>
I. DESCRIPTION
A remote buffer overflow vulnerability has been found in mod_tls module of
ProFTPD server.
The vulnerability could allow a remote un-authenticated attacker to gain root
privileges.
II. DETAILS
Let's have a look at the code (ProFTPD version 1.3.0):
contrib/mod_tls.c:
"""
static char *tls_x509_name_oneline(X509_NAME *x509_name) {
static char buf[256] = {'