CVE-2006-6171 - CVE House
Back to Database
Status published High CVE-2006-6171

ProFTPD 1.3.0a and earlier does not properly set the buffer...

Vulnerability Description

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-6171

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

proftpd project

View all reports →

Affected Software

proftpd
Vulnerable Versions:
0

Timeline

Official Publish: November 30th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.