← Vulnerability feed

Vulnerability record · CVE-2006-5815 · published 8 November 2006

CVE-2006-5815: ProFTPD sreplace stack buffer overflow allows remote code execution

PProftpd Project · Proftpd

ProFTPD 1.3.0 and earlier contains a stack-based buffer overflow in the sreplace function. A remote attacker, probably authenticated, can trigger the overflow to crash the daemon and potentially execute arbitrary code, as demonstrated by the public vd_proftpd.pm exploit. Because ProFTPD is widely deployed as an FTP server, a working remote exploit against it is a serious exposure.

10.0 CVSS 2.0 High EPSS 74% · top 0.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
50References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with a network-reachable stack overflow, a public exploit module and very high EPSS make this a top remediation priority despite the absence of KEV listing.

What it is

ProFTPD 1.3.0 and earlier contains a stack-based buffer overflow in the sreplace function. A remote attacker, probably authenticated, can trigger the overflow to crash the daemon and potentially execute arbitrary code, as demonstrated by the public vd_proftpd.pm exploit. Because ProFTPD is widely deployed as an FTP server, a working remote exploit against it is a serious exposure.

Impact

An attacker can cause a denial of service and, per the description, execute arbitrary code in the context of the ProFTPD process, which typically runs with elevated privileges. Successful exploitation could yield full control of the FTP service host.

Attack surface

Reached over the network via the FTP service (CVSS vector AV:N/AC:L/Au:N), so no user interaction is required. The description states the attacker is 'probably authenticated', so valid FTP credentials may be needed, though the vector itself scores no authentication.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.738 (99.45th percentile) and a public exploit module (vd_proftpd.pm) is referenced, indicating active exploitation is likely.

What to do

  • Upgrade ProFTPD to a version later than 1.3.0 that contains the sreplace fix; apply the vendor patch referenced in the ProFTPD bug report.
  • Apply the distribution security updates listed in the Debian, Gentoo, Mandriva, Slackware, OpenPKG and Trustix advisories.
  • Restrict FTP access to trusted networks and require strong authentication to limit exposure to the vulnerable code path.
  • Run ProFTPD with least privilege and isolate it (chroot, dedicated account, container) to limit the impact of code execution.

Detection

  • Monitor ProFTPD logs for crashes, restarts or abnormal termination that could indicate overflow attempts.
  • Inspect FTP command traffic for unusually long or malformed arguments reaching the sreplace code path.
  • Watch for unexpected child processes or outbound connections spawned by the ProFTPD process, which may indicate successful code execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.proftpd.org/show_bug.cgi?id=2858
http://gleg.net/vulndisco_meta.shtml
http://secunia.com/advisories/22803 Vendor Advisory
http://secunia.com/advisories/22821 Vendor Advisory
http://secunia.com/advisories/23000 Vendor Advisory
http://secunia.com/advisories/23069 Vendor Advisory
http://secunia.com/advisories/23125 Vendor Advisory
http://secunia.com/advisories/23174 Vendor Advisory
http://secunia.com/advisories/23179 Vendor Advisory
http://secunia.com/advisories/23184 Vendor Advisory
http://secunia.com/advisories/23207 Vendor Advisory
http://securitytracker.com/id?1017167
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.502491
http://www.debian.org/security/2006/dsa-1222
http://www.gentoo.org/security/en/glsa/glsa-200611-26.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217-1
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.035-proftpd.html
http://www.securityfocus.com/archive/1/452760/100/200/threaded
http://www.securityfocus.com/bid/20992
http://www.trustix.org/errata/2006/0066/
http://www.trustix.org/errata/2006/0070
http://www.vupen.com/english/advisories/2006/4451 Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820
https://exchange.xforce.ibmcloud.com/vulnerabilities/30147
http://bugs.proftpd.org/show_bug.cgi?id=2858
http://gleg.net/vulndisco_meta.shtml
http://secunia.com/advisories/22803 Vendor Advisory
http://secunia.com/advisories/22821 Vendor Advisory
http://secunia.com/advisories/23000 Vendor Advisory
http://secunia.com/advisories/23069 Vendor Advisory
http://secunia.com/advisories/23125 Vendor Advisory
http://secunia.com/advisories/23174 Vendor Advisory
http://secunia.com/advisories/23179 Vendor Advisory
http://secunia.com/advisories/23184 Vendor Advisory
http://secunia.com/advisories/23207 Vendor Advisory
http://securitytracker.com/id?1017167
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.502491
http://www.debian.org/security/2006/dsa-1222
http://www.gentoo.org/security/en/glsa/glsa-200611-26.xml

Track CVE-2006-5815 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0500Proftpd project proftpd vulnerabilitySQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute…EPSS 18%10.0CVE-1999-0911Proftpd project proftpd vulnerabilityBuffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested…EPSS 38%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%9.0CVE-2003-0831ProFTPD ASCII mode newline handling buffer overflow allows remote code executionProFTPD 1.2.7 through 1.2.9rc2 fails to properly translate newline characters when transferring files in ASCII mode, resulting in a buffer overflow. …EPSS 58%analysed7.5CVE-2009-0542ProFTPD mod_sql SQL injection via percent character in usernameProFTPD Server 1.3.1 through 1.3.2rc2 contains a SQL injection flaw in mod_sql: a "%" character in the username introduces a single quote during vari…EPSS 74%analysed7.5CVE-2006-6170Proftpd project proftpd vulnerabilityBuffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allo…EPSS 17%7.5CVE-2006-6171Proftpd project proftpd vulnerabilityProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to …EPSS 9.7%7.5CVE-2005-4816Proftpd project proftpd vulnerabilityBuffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2006-5815), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.