PCMan FTP Server Buffer Overflow Vulnerability in DIR Command Handler

Vulnerability

A critical buffer overflow vulnerability has been identified in PCMan FTP Server version 2.0.7. The issue arises in the DIR command handler, where an unknown function improperly manages input buffer sizes, allowing for remote exploitation. This vulnerability has been publicly disclosed and is available as a proof-of-concept exploit.

Impact

Exploitation of this vulnerability can lead to a buffer overflow, allowing for arbitrary code execution on the affected system.

Reproduction

The vulnerability can be reproduced by sending an excessive amount of data through the 'DIR' command. This causes the application to crash, indicating a buffer overflow condition. After identifying the offset needed to exploit the vulnerability, the exploit can be executed by connecting to the FTP server and sending the crafted payload via the 'DIR' command.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.