CVE-2009-4593 Information

Description

The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a ‘\0’ character at the end of the string value of the ut.bu_host structure member which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.

Reference

http://bftpd.sourceforge.net/downloads/CHANGELOG http://bftpd.sourceforge.net/news.html032130 http://secunia.com/advisories/37185 http://www.securityfocus.com/bid/36820 http://www.vupen.com/english/advisories/2009/3032

Share on: