TNFTPD < 20040811 Globbing Overflow

Medium Nessus Network Monitor Plugin ID 3836


The remote host is vulnerable to a buffer overflow.


The remote host is running TNFTPD, a port of the NetBSD FTP daemon. This version of TNFTPD is vulnerable to a remote buffer overflow. The flaw is within the glob.c function. An attacker exploiting this flaw would need to authenticate to the server and then pass a malformed string that would be interpreted by the glob function. Successful exploitation results in the attacker executing arbitrary code on the remote system.


Upgrade to version 20040811 or higher.

Plugin Details

Severity: Medium

ID: 3836

Family: FTP Servers

Published: 2006/12/01

Updated: 2019/03/06

Dependencies: 1803, 1804, 3222

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:ND

CVSS v3.0

Base Score: 6.2

Temporal Score: 5.5

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:X

Vulnerability Information

CPE: cpe:/o:netbsd:netbsd

Reference Information

CVE: CVE-2006-6652

BID: 21377