CVE-2006-6576
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 67%
from disclosure to weapon1500 days
Published on NVDDec 15
1st PoC+1500d
metasploit+1500d
exploitation probability
67%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.
Affected products
n/a · n/apublic PoCs found — 5✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16036exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/49629exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17355cve_referencepacketstormsecurity.com/files/161711/Golden-FTP-Server-4.70-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/16036unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/161711/Golden-FTP-Server-4.70-Buffer-Overflow.htmlhttp://retrogod.altervista.org/golden_heap.htmlhttp://secunia.com/advisories/23323http://www.exploit-db.com/exploits/16036http://www.securityfocus.com/bid/45924http://www.securityfocus.com/bid/45957http://www.vupen.com/english/advisories/2006/4936