Vulnerability record · CVE-2006-5815 · published 8 November 2006
CVE-2006-5815: ProFTPD sreplace stack buffer overflow allows remote code execution
PProftpd Project · Proftpd
ProFTPD 1.3.0 and earlier contains a stack-based buffer overflow in the sreplace function. A remote attacker, probably authenticated, can trigger the overflow to crash the daemon and potentially execute arbitrary code, as demonstrated by the public vd_proftpd.pm exploit. Because ProFTPD is widely deployed as an FTP server, a working remote exploit against it is a serious exposure.
Description
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with a network-reachable stack overflow, a public exploit module and very high EPSS make this a top remediation priority despite the absence of KEV listing.
What it is
ProFTPD 1.3.0 and earlier contains a stack-based buffer overflow in the sreplace function. A remote attacker, probably authenticated, can trigger the overflow to crash the daemon and potentially execute arbitrary code, as demonstrated by the public vd_proftpd.pm exploit. Because ProFTPD is widely deployed as an FTP server, a working remote exploit against it is a serious exposure.
Impact
An attacker can cause a denial of service and, per the description, execute arbitrary code in the context of the ProFTPD process, which typically runs with elevated privileges. Successful exploitation could yield full control of the FTP service host.
Attack surface
Reached over the network via the FTP service (CVSS vector AV:N/AC:L/Au:N), so no user interaction is required. The description states the attacker is 'probably authenticated', so valid FTP credentials may be needed, though the vector itself scores no authentication.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.738 (99.45th percentile) and a public exploit module (vd_proftpd.pm) is referenced, indicating active exploitation is likely.
What to do
- Upgrade ProFTPD to a version later than 1.3.0 that contains the sreplace fix; apply the vendor patch referenced in the ProFTPD bug report.
- Apply the distribution security updates listed in the Debian, Gentoo, Mandriva, Slackware, OpenPKG and Trustix advisories.
- Restrict FTP access to trusted networks and require strong authentication to limit exposure to the vulnerable code path.
- Run ProFTPD with least privilege and isolate it (chroot, dedicated account, container) to limit the impact of code execution.
Detection
- Monitor ProFTPD logs for crashes, restarts or abnormal termination that could indicate overflow attempts.
- Inspect FTP command traffic for unusually long or malformed arguments reaching the sreplace code path.
- Watch for unexpected child processes or outbound connections spawned by the ProFTPD process, which may indicate successful code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5815 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5815), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.