Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service. | |
Title | Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption | |
Weaknesses | CWE-704 CWE-787 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-21T20:15:15.812Z
Updated: 2025-08-21T20:53:36.121Z
Reserved: 2025-08-20T18:52:46.120Z
Link: CVE-2010-20115

Updated: 2025-08-21T20:53:20.956Z

Status : Received
Published: 2025-08-21T21:15:34.313
Modified: 2025-08-21T21:15:34.313
Link: CVE-2010-20115

No data.