CVE-2012-10035 PUBLISHED

Turbo FTP Server 1.30.823/826 PORT Command Buffer Overflow

Assigner: VulnCheck
Reserved: 05.08.2025 Published: 05.08.2025 Updated: 07.08.2025

Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor TurboSoft, Inc.
Product TurboFTP Server
Versions Default: unaffected
  • Version 1.30.823 is affected
  • Version 1.30.826 is affected

Credits

  • Zhao Liang finder

References

Problem Types

  • CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE

Impacts

  • CAPEC-100 Overflow Buffers