Back

CRITICAL

Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption

Published Aug 21, 2025

Description

Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 21, 2025
Updated May 15, 2026
Reserved Aug 20, 2025
CISA Vulnrichment
Updated Aug 21, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a