Security Advisory

CVE-2010-20115

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-21 20:15:15
Last updated 2026-05-15 11:13:34
Assigner VulnCheck
CVSS score 9.3
State PUBLISHED

Description

Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.