Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.
Link | Tags |
---|---|
http://www.osvdb.org/4029 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15276 | vdb entry |
http://www.securityfocus.com/bid/9715 | vdb entry patch vendor advisory |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html | mailing list |
https://www.debian.org/security/2004/dsa-447 | vendor advisory |