CVE-2006-6171

N/A Unknown
Published: November 30, 2006 Modified: April 23, 2026
View on NVD

Description

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://proftp.cvs.sourceforge.net/proftp/proftpd/src/main.c?r1=1.292&r2=1.293&sortby=date
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/23174
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23179
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23184
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23207
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23329
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1218
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1222
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200611-26.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2006/0070
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
4.8%
90th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

proftpd_project