CVE-2011-5164: Buffer Overflow
Published Sep 15, 2012
·Updated
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
Affected Software
14 affected components
VanDyke AbsoluteFTP=1.9.6
VanDyke AbsoluteFTP=2.0.3
VanDyke AbsoluteFTP=2.0.4
VanDyke AbsoluteFTP=2.0.5
VanDyke AbsoluteFTP=2.2.1
VanDyke AbsoluteFTP=2.2.2
VanDyke AbsoluteFTP=2.2.3
VanDyke AbsoluteFTP=2.2.4
VanDyke AbsoluteFTP=2.2.5
VanDyke AbsoluteFTP=2.2.6
VanDyke AbsoluteFTP=2.2.7
VanDyke AbsoluteFTP=2.2.8
VanDyke AbsoluteFTP=2.2.9
VanDyke AbsoluteFTP=2.2.10
Event History
Sep 15, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5164?
CVE-2011-5164 is rated as a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2011-5164?
To fix CVE-2011-5164, upgrade to the latest version of VanDyke Software AbsoluteFTP that addresses this vulnerability.
3
What versions of AbsoluteFTP are affected by CVE-2011-5164?
CVE-2011-5164 affects AbsoluteFTP versions from 1.9.6 to 2.2.10.
4
What type of vulnerability is CVE-2011-5164?
CVE-2011-5164 is a stack-based buffer overflow vulnerability.
5
Can CVE-2011-5164 be exploited remotely?
Yes, CVE-2011-5164 can be exploited remotely when a crafted file name is processed by the LIST command.