Vulnerability record · CVE-2003-0558 · published 18 August 2003
CVE-2003-0558: LeapFTP buffer overflow via PASV IP address response
Leapware · Leapftp
LeapFTP 2.7.3.600 contains a buffer overflow that is triggered when the client processes a long IP address in a PASV response from an FTP server. Because the overflow occurs in the client, a malicious or compromised FTP server can corrupt memory and potentially execute code on the connecting user's machine. The record is old and thin, with no vendor advisory or patch reference supplied.
Description
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution in a client via a malicious server with a high EPSS score, though the lack of KEV listing and confirmed exploit lowers it below critical.
What it is
LeapFTP 2.7.3.600 contains a buffer overflow that is triggered when the client processes a long IP address in a PASV response from an FTP server. Because the overflow occurs in the client, a malicious or compromised FTP server can corrupt memory and potentially execute code on the connecting user's machine. The record is old and thin, with no vendor advisory or patch reference supplied.
Impact
An attacker controlling the FTP server can execute arbitrary code in the context of the LeapFTP user, giving full control of that workstation. At minimum, the flaw can crash the client.
Attack surface
Reached over the network when the victim connects to an attacker-controlled or compromised FTP server that returns an oversized IP address in its PASV reply. No authentication to the client is required, but the victim must initiate the FTP connection; the CVSS vector shows network access with no authentication.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, though EPSS is high at roughly 0.56 (99th percentile), indicating elevated predicted exploitation likelihood. No public exploit is confirmed by the supplied data.
What to do
- Upgrade or replace LeapFTP 2.7.3.600 with a maintained FTP client, since no vendor patch is referenced in this record.
- Block outbound FTP (TCP 21) and PASV data channels at the perimeter where business use does not require them.
- Restrict FTP client use to trusted, known servers and avoid connecting to untrusted or user-supplied FTP hosts.
- Where FTP must remain, run the client in a low-privilege sandbox or separate host to limit code execution impact.
Detection
- Monitor for LeapFTP process crashes or abnormal termination following FTP PASV connections.
- Inspect FTP server responses for unusually long PASV IP address fields or malformed PASV replies.
- Alert on LeapFTP spawning unexpected child processes or making outbound connections after an FTP session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0558 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0558), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.