Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.
Link | Tags |
---|---|
http://security.gentoo.org/glsa/glsa-200502-26.xml | vendor advisory |
http://bugs.gentoo.org/show_bug.cgi?id=81894 | exploit vendor advisory |