Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.
| Software | From | Fixed in |
|---|---|---|
| grant_averett / ceberus_ftp_server | 1.1 | 1.1.x |
| grant_averett / ceberus_ftp_server | 1.0 | 1.0.x |
| grant_averett / ceberus_ftp_server | 1.22 | 1.22.x |
| grant_averett / ceberus_ftp_server | 1.5 | 1.5.x |
| grant_averett / ceberus_ftp_server | 1.2 | 1.2.x |
| grant_averett / ceberus_ftp_server | 1.01 | 1.01.x |
| grant_averett / ceberus_ftp_server | 1.3 | 1.3.x |