Metrics
Affected Vendors & Products
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bftpd
Bftpd bftpd |
|
| Vendors & Products |
Bftpd
Bftpd bftpd |
Mon, 20 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 19 Oct 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing manipulation can lead to heap-based buffer overflow. It is possible to launch the attack on the local host. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | bftpd Configuration File options.c expand_groups heap-based overflow | |
| Weaknesses | CWE-119 CWE-122 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-19T22:02:08.502Z
Updated: 2025-10-20T18:04:29.574Z
Reserved: 2025-10-19T03:06:35.660Z
Link: CVE-2025-11947
Updated: 2025-10-20T03:41:07.489Z
Status : Awaiting Analysis
Published: 2025-10-19T22:15:37.080
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-11947
No data.