ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability

BID:6478

Info

ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability

Bugtraq ID: 6478
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Dec 24 2002 12:00AM
Updated: Dec 24 2002 12:00AM
Credit: Discovery of this vulnerability is credited to spinez.
Vulnerable: NcFTP Software NcFTPD 2.7.1
Not Vulnerable:

Discussion

ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability

A vulnerability has been reported for ncftpd. The problem occurs in the STAT function when used in conjuction with file globbing. This issue can be triggered by a malicious STAT request for a directory with a filename of excessive length. The problem is due to filename expansion which is due to special characters used during the request.

It should be noted that this vulnerability has been reported to exist in version 2.7.1.

The vendor has announced that nctpd is in fact not vulnerable to this issue.

Symantec has been unable to reproduce this vulnerability.

Exploit / POC

ncftpd STAT File Globbing Remote Buffer Overflow Vulnerability

It has been confirmed that an exploit for this vulnerability is available. It should be noted however that reports indicate this exploit may be a fake and is in fact a trojan.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report