CVE-2006-6171
Last modified
CVE-2006-6171 is a vulnerability of currently unknown severity. ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. EPSS estimates a 9.30% chance of exploitation in the next 30 days.
Description
ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Proftpd Project | Proftpd | <= 1.3.0a |
References
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6171?
How severe is CVE-2006-6171?
How do I fix CVE-2006-6171?
Are you affected by CVE-2006-6171?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
