CVE-2016-20046

zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer allocated in strcpy_chk to overwrite the instruction pointer and execute shellcode with user privileges.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-28 12:16

Updated : 2026-03-30 13:26


NVD link : CVE-2016-20046

Mitre link : CVE-2016-20046

CVE.ORG link : CVE-2016-20046


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write