|
WarFTPd contains a format string flaw in war-ftpd.exe. The issue is triggered as format string specifiers (e.g. %s and %x) are not properly sanitized in usernames supplied during the authentication process. With a specially crafted request, a remote attacker can crash the service causing a denial of service.
|