Metrics
Affected Vendors & Products
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Bftpd Bftpd bftpd | |
| Vendors & Products | Bftpd Bftpd bftpd | 
Mon, 20 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sun, 19 Oct 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing manipulation can lead to heap-based buffer overflow. It is possible to launch the attack on the local host. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | bftpd Configuration File options.c expand_groups heap-based overflow | |
| Weaknesses | CWE-119 CWE-122 | |
| References |  | |
| Metrics | cvssV2_0 
 
 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-19T22:02:08.502Z
Updated: 2025-10-20T18:04:29.574Z
Reserved: 2025-10-19T03:06:35.660Z
Link: CVE-2025-11947
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-20T03:41:07.489Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-19T22:15:37.080
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-11947
 Redhat
                        Redhat
                    No data.