WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
Software | From | Fixed in |
---|---|---|
war_ftp_daemon / war_ftp_daemon | 1.8 | 1.8.x |
war_ftp_daemon / war_ftp_daemon | 1.82_rc9 | 1.82_rc9.x |