CVE-2008-4572 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 60.7% (pctl 99)
Patch early
A public exploit exists.
Description
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 60.69% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| guildftpd | guildftpd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service | 2008-10-12 |
References
- http://secunia.com/advisories/32218
- http://securityreason.com/securityalert/4422
- http://www.securityfocus.com/bid/31729
- http://www.vupen.com/english/advisories/2008/2794
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45818
- https://www.exploit-db.com/exploits/6738
- http://secunia.com/advisories/32218
- http://securityreason.com/securityalert/4422
- http://www.securityfocus.com/bid/31729
- http://www.vupen.com/english/advisories/2008/2794
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45818
- https://www.exploit-db.com/exploits/6738
→ the Explorer · watch your stack · NVD