CVE-2010-20115 Details
Description
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.
A memory corruption vulnerability has been identified in Arcane Software's Vermillion FTP Daemon (vftpd) versions through 1.31. The issue is triggered by a malformed FTP PORT command, leading to an out-of-bounds array access during input parsing. This flaw allows an attacker to manipulate stack memory, with the potential to execute arbitrary code. Exploitation requires direct access to the FTP service and is limited to a single attempt if the daemon is installed as a Windows service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 21, 2025CISA-ADP
Assessed Aug 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-704 | Incorrect Type Conversion or Cast | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Arcane Software Vermillion FTP Daemon | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | New CVE Received | [email protected] |
| Aug 21, 2025 | CVE Modified | CISA-ADP |
Volerion