Vulnerabilities > CVE-2005-3683 - Buffer Overflow vulnerability in FreeFTPD User Command

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
freeftpd
exploit available
metasploit

Summary

Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command.

Exploit-Db

  • descriptionFreeFTPD <= 1.0.8 (USER) Remote Buffer Overflow Exploit. CVE-2005-3683,CVE-2005-3684. Remote exploit for windows platform
    idEDB-ID:1330
    last seen2016-01-31
    modified2005-11-17
    published2005-11-17
    reporterExpanders
    sourcehttps://www.exploit-db.com/download/1330/
    titleFreeFTPD <= 1.0.8 USER Remote Buffer Overflow Exploit
  • descriptionfreeFTPd 1.0 Username Overflow. CVE-2005-3683. Remote exploit for windows platform
    idEDB-ID:16707
    last seen2016-02-02
    modified2010-07-03
    published2010-07-03
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16707/
    titlefreeFTPd 1.0 Username Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in the freeFTPd multi-protocol file transfer service. This flaw can only be exploited when logging has been enabled (non-default).
idMSF:EXPLOIT/WINDOWS/FTP/FREEFTPD_USER
last seen2020-06-01
modified2017-07-24
published2006-01-08
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3683
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/freeftpd_user.rb
titlefreeFTPd 1.0 Username Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83039/freeftpd_user.rb.txt
idPACKETSTORM:83039
last seen2016-12-05
published2009-11-26
reporterMC
sourcehttps://packetstormsecurity.com/files/83039/freeFTPd-1.0-Username-Overflow.html
titlefreeFTPd 1.0 Username Overflow

Saint

bid15457
descriptionFreeFTPd user name buffer overflow
idftp_freeftpd
osvdb20909
titlefreeftpd_user_bo
typeremote