← Vulnerability feed

Vulnerability record · CVE-2005-2373 · published 26 July 2005

CVE-2005-2373: SlimFTPd buffer overflow in LIST, DELE and RNFR commands

WWhitsoft Development · Slimftpd

SlimFTPd 3.15 and 3.16 contain a buffer overflow that is triggered by a long directory name passed to the LIST, DELE or RNFR commands. A remote authenticated FTP user can overflow the buffer and potentially execute arbitrary code on the server. The flaw is serious because it gives an authenticated user a path to full compromise of the FTP service.

7.2 CVSS 2.0 High EPSS 46% · top 1.2%
7.2CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows remote authenticated code execution and has a high EPSS score, though exploitation is limited by the need for valid FTP credentials.

What it is

SlimFTPd 3.15 and 3.16 contain a buffer overflow that is triggered by a long directory name passed to the LIST, DELE or RNFR commands. A remote authenticated FTP user can overflow the buffer and potentially execute arbitrary code on the server. The flaw is serious because it gives an authenticated user a path to full compromise of the FTP service.

Impact

An attacker who can authenticate to the FTP server can execute arbitrary code with the privileges of the SlimFTPd process. That typically means full control of the service account and any files or network access it holds.

Attack surface

The flaw is reached over the FTP protocol by sending an oversized directory name in a LIST, DELE or RNFR command. Authentication is required, and no user interaction beyond the FTP session is needed.

Exploitation

No CISA KEV entry and no public exploit tags are present in the record, but EPSS is high at roughly 0.46 (98.7th percentile), indicating elevated predicted exploitation activity. The record does not confirm that working exploits exist.

What to do

  • Upgrade SlimFTPd to a version later than 3.16 if one is available; the record does not list fixed versions, so verify with the vendor.
  • If no fixed version exists, restrict FTP access to trusted networks and disable or block the LIST, DELE and RNFR commands where possible.
  • Enforce strong authentication and least privilege for FTP accounts so only necessary users can reach the service.
  • Run SlimFTPd under a low-privilege account and isolate it from sensitive file systems and internal networks.
  • Monitor vendor and vulnerability feeds for a patched release, since the referenced vendor URL is flagged as repurposed.

Detection

  • Inspect FTP server logs for LIST, DELE or RNFR commands containing unusually long directory names.
  • Alert on FTP sessions that issue malformed or oversized path arguments followed by process crashes or restarts.
  • Monitor the SlimFTPd process for unexpected child processes, file writes or outbound connections after FTP commands.
  • Baseline normal FTP command lengths and flag deviations that exceed expected directory name sizes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2373 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-2373), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.