Vulnerability record · CVE-1999-0256 · published 1 February 1998
CVE-1999-0256: War FTP buffer overflow allows remote command execution
Jgaa · Warftpd
War FTP contains a buffer overflow that lets a remote attacker execute commands. The flaw is network-reachable and requires no authentication, so any host running the affected server is exposed. The record is thin: it names no affected version and gives no patch detail.
Description
Buffer overflow in War FTP allows remote execution of commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a very high EPSS score, though the record lacks version and patch specifics.
What it is
War FTP contains a buffer overflow that lets a remote attacker execute commands. The flaw is network-reachable and requires no authentication, so any host running the affected server is exposed. The record is thin: it names no affected version and gives no patch detail.
Impact
An attacker can run commands on the FTP server host, potentially taking full control of the machine under the service account.
Attack surface
Reached over the network via the FTP service (CVSS vector AV:N/AC:L/Au:N), with no authentication and no user interaction required.
Exploitation
Not listed in CISA KEV and no exploit references are tagged, but EPSS is 0.72857 (99.4th percentile), indicating high predicted exploitation activity.
What to do
- Apply the vendor patch or upgrade War FTP to a fixed release; no fixed version is stated in this record, so confirm with the vendor.
- If no patch is available, restrict FTP access to trusted networks and disable the service where not needed.
- Run the FTP service under a low-privilege account and isolate it from sensitive data.
- Replace War FTP with a maintained FTP server if the product is no longer supported.
Detection
- Monitor FTP service logs for oversized or malformed commands and unexpected disconnects.
- Alert on child processes spawned by the FTP daemon, especially shells or command interpreters.
- Watch for outbound connections from the FTP host that do not match normal FTP traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-1999-0256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-0256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.