CRITICAL
freeFTPd <= 1.0.10 PASS Command Stack-Based Buffer Overflow
Published Jul 31, 2025
9.3
CRITICALCVSS 4.0
EPSS 2.55%
Description
A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PASS command. When an attacker sends a specially crafted password string, the application fails to validate input length, resulting in memory corruption. This can lead to denial of service or arbitrary code execution. Exploitation requires the anonymous user account to be enabled.
Affected products
-
- Version 0StatusaffectedConstraints<=1.0.10
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-7252 Advisory
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/freeftpd_pass.rb exploit
- https://www.exploit-db.com/exploits/27747 exploit
- https://www.vulncheck.com/advisories/freeftpd-pass-command-stack-based-buffer-overflow third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-7252 | Advisory | |
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/freeftpd_pass.rb | exploit | |
| https://www.exploit-db.com/exploits/27747 | exploit | |
| https://www.vulncheck.com/advisories/freeftpd-pass-command-stack-based-buffer-overflow | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 31, 2025
Updated May 15, 2026
Reserved Jul 30, 2025
Link CVE-2013-10042
CISA Vulnrichment
Updated Jul 31, 2025
ENISA EUVD
EUVD-2013-7252 Assigner VulnCheck
Published Jul 31, 2025
Updated May 15, 2026
Exploited since n/a
Link EUVD-2013-7252