Executive brief
A vulnerability exists in the Washington University FTP (wu-ftpd) server, a common tool used for transferring files over a network. An attacker can trigger a crash of the service by sending a specifically crafted command, leading to a denial of service. This prevents legitimate users from accessing or uploading files, potentially disrupting business operations that rely on automated file transfers.
Technical details
A buffer overflow vulnerability exists in the PASV command implementation of the wu-ftpd server. The flaw is triggered when the server processes a malformed or unexpected PASV request, leading to memory corruption and a subsequent core dump. This is a remote, unauthenticated attack vector that results in a denial of service (DoS). While the primary impact is service instability, buffer overflows in this era of software often carried risks of arbitrary code execution, though only denial of service is confirmed in this specific advisory. Users should upgrade to a patched version of wu-ftpd or migrate to a more modern FTP daemon.
Affected products
- Washington University wu-ftpd
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD