Vulnerabilities > CVE-2006-6576 - Out-Of-Bounds Write vulnerability in Goldenftpserver Golden FTP Server 1.92

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
goldenftpserver
CWE-787
exploit available
metasploit

Summary

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

Vulnerable Configurations

Part Description Count
Application
Goldenftpserver
1

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionGoldenFTP PASS Stack Buffer Overflow. CVE-2006-6576. Remote exploit for windows platform
    idEDB-ID:17355
    last seen2016-02-02
    modified2011-06-02
    published2011-06-02
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/17355/
    titleGolden FTP 4.70 - PASS Stack Buffer Overflow
  • descriptionGolden FTP Server 4.70 - PASS Command Buffer Overflow Exploit. CVE-2006-6576. Remote exploit for windows platform
    fileexploits/windows/remote/16036.rb
    idEDB-ID:16036
    last seen2016-02-01
    modified2011-01-23
    platformwindows
    port
    published2011-01-23
    reportercd1zz and iglesiasgg
    sourcehttps://www.exploit-db.com/download/16036/
    titleGolden FTP Server 4.70 - PASS Command Buffer Overflow Exploit
    typeremote

Metasploit

descriptionThis module exploits a vulnerability in the Golden FTP service, using the PASS command to cause a buffer overflow. Please note that in order trigger the vulnerable code, the victim machine must have the "Show new connections" setting enabled. By default, this option is unchecked.
idMSF:EXPLOIT/WINDOWS/FTP/GOLDENFTP_PASS_BOF
last seen2020-05-26
modified2017-07-24
published2011-06-02
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6576
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/goldenftp_pass_bof.rb
titleGoldenFTP PASS Stack Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/101952/goldenftp_pass_bof.rb.txt
idPACKETSTORM:101952
last seen2016-12-05
published2011-06-03
reporterbannedit
sourcehttps://packetstormsecurity.com/files/101952/GoldenFTP-PASS-Stack-Buffer-Overflow.html
titleGoldenFTP PASS Stack Buffer Overflow