VDB
CVE-2010-4221
CVE-2010-4221
PUBLISHED
CVSS 10 CRITICAL
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.
EPSS 92.05% · 99.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
92.05%
99.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| proftpd | proftpd | 1.3.2, 1.3.2, 1.3.2 |
Timeline
- Nov 9, 2010 CVE Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 17, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Jul 2, 2024 EPSS Score
- Aug 7, 2024 CVE Updated
- Dec 17, 2024 EPSS Score
- Dec 27, 2024 EPSS Score
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Mar 17, 2025 EPSS Score
References
- http://www.securityfocus.com/bid/44562 url
- http://www.proftpd.org/docs/NEWS-1.3.3c url
- FEDORA-2010-17091 vendor-advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-229/ url
- 42217 third-party-advisory
- FEDORA-2010-17098 vendor-advisory
- FEDORA-2010-17220 vendor-advisory
- ADV-2010-2941 vdb
- ADV-2010-2962 vdb
- 42052 third-party-advisory
- http://bugs.proftpd.org/show_bug.cgi?id=3521 url
- MDVSA-2010:227 vendor-advisory
- ADV-2010-2959 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-4221 advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-229 url