The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/36820 | vdb entry patch |
http://secunia.com/advisories/37185 | third party advisory vendor advisory |
http://bftpd.sourceforge.net/downloads/CHANGELOG | |
http://www.vupen.com/english/advisories/2009/3032 | vdb entry patch vendor advisory |
http://bftpd.sourceforge.net/news.html#032130 | patch |