id: CVE-2006-2173 info: name: FileZilla FTP Server 2.2.22 - Buffer Overflow author: pussycat0x severity: medium description: | FileZilla FTP Server version 2.2.22 contains a buffer overflow vulnerability that allows remote authenticated attackers to cause denial of service and potentially execute arbitrary code. The vulnerability can be triggered by sending excessively long PORT or PASS commands followed by MLSD commands, or through the remote interface. impact: | Authenticated attackers can send excessively long PORT or PASS commands followed by MLSD commands to trigger buffer overflow, causing denial of service or potentially executing arbitrary code on the FTP server. remediation: | Update FileZilla FTP Server to a version newer than 2.2.22 that properly validates command length and prevents buffer overflow vulnerabilities. reference: - http://marc.info/?l=bugtraq&m=114658586018818&w=2 - http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-05-03 - https://exchange.xforce.ibmcloud.com/vulnerabilities/26303 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:P cvss-score: 6.4 cve-id: CVE-2006-2173 epss-score: 0.06499 epss-percentile: 0.93043 cpe: cpe:2.3:a:filezilla:filezilla_server:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: filezilla product: filezilla_server shodan-query: product:"FileZilla" tags: cve,cve2006,network,ftp,filezilla,tcp,passive,buffer-overflow,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'FileZilla')" - "contains(version, '2.2.22')" condition: and extractors: - type: regex group: 1 name: version regex: - "FileZilla Server version ([0-9.]+)" # digest: 490a0046304402204fa207f91394f6b3bce40a6931feeb73c6a51586cc616fb2d72787ca94b589180220300e91f5492a8977392c69da6d9ae4a6b6155e9149441195e7da1209ea082a44:922c64590222798bb761d5b6d8e72950