← back
CVE-2016-20046highCWE-787

zFTP Client 20061220+dfsg3-4.1 Local Buffer Overflow

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.6epss 0.1%
exploitation probability
0.1%top 95% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer allocated in strcpy_chk to overwrite the instruction pointer and execute shellcode with user privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
zFTP · zFTP Client
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.