|
WU-FTPD contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is triggered when when the 'ftpglob()' function fails to properly set the 'globerr' variable when the malformed string '~{' is inserted after a valid command by a valid user. This causes the heap to become corrupt and potentially allow a remote attacker to place and point to arbitrary commands on the heap. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|