Vulnerability record · CVE-2007-1567 · published 21 March 2007
CVE-2007-1567: War FTP Daemon stack buffer overflow allows remote code execution
WWar Ftp Daemon · War Ftp Daemon
War FTP Daemon 1.65 (and possibly earlier) contains a stack-based buffer overflow reachable by remote attackers through unspecified vectors. The flaw can crash the service or allow arbitrary code execution, and the record notes it may duplicate CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but the lack of detail from the discoverer prevents confirmation.
Description
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely reachable without authentication and can yield code execution, but the record lacks confirmed affected versions, a vendor fix, and KEV listing.
What it is
War FTP Daemon 1.65 (and possibly earlier) contains a stack-based buffer overflow reachable by remote attackers through unspecified vectors. The flaw can crash the service or allow arbitrary code execution, and the record notes it may duplicate CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but the lack of detail from the discoverer prevents confirmation.
Impact
A remote attacker can cause a denial of service or execute arbitrary code in the context of the FTP daemon, which typically runs with service privileges.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and no user interaction. The exact protocol command or input that triggers the overflow is not specified in the record.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is 0.50549 (98.86th percentile), and the only reference tagged as a patch is an Immunity proof-of-concept archive, indicating public exploit material exists.
What to do
- Upgrade or replace War FTP Daemon 1.65; the product is long unmaintained, so migrate to a supported FTP server if no fixed release exists.
- Restrict FTP service exposure to trusted networks and block port 21 from the internet where possible.
- Run the daemon under a low-privilege account and isolate it in a sandbox or container to limit code execution impact.
- Monitor vendor and CVE databases for a confirmed fix or clarification of the duplicate CVE relationship before relying on version-based detection.
Detection
- Monitor FTP daemon process crashes and unexpected restarts, which may indicate denial-of-service attempts.
- Alert on child processes spawned by the FTP service, a strong signal of successful code execution.
- Inspect FTP command logs for unusually long or malformed arguments preceding a crash.
- Correlate network connections to port 21 with host-based crash or process-creation telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1567 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.