Vulnerability record · CVE-2008-4572 · published 15 October 2008
CVE-2008-4572: GuildFTPd heap corruption via CWD and LIST command arguments
Guildftpd · Guildftpd
GuildFTPd 0.999.14 (and possibly other versions) mishandles long arguments to the CWD and LIST commands, triggering heap corruption from an improper free call and possibly a heap-based buffer overflow. The flaw is remotely reachable over the network without authentication, so it matters for any exposed FTP service running this software.
Description
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated heap corruption with public exploit code and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
GuildFTPd 0.999.14 (and possibly other versions) mishandles long arguments to the CWD and LIST commands, triggering heap corruption from an improper free call and possibly a heap-based buffer overflow. The flaw is remotely reachable over the network without authentication, so it matters for any exposed FTP service running this software.
Impact
An attacker can crash the FTP server and potentially execute arbitrary code in its context, which typically runs with the privileges of the service account.
Attack surface
Reached over the network through the FTP service by sending crafted CWD or LIST commands; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.60692 (99.1st percentile) and a public Exploit-DB entry (6738) exists, indicating known public exploit code.
What to do
- Upgrade GuildFTPd to a version later than 0.999.14 if one is available; the record does not name a fixed version, so confirm with the vendor.
- If no fix exists, restrict FTP access to trusted networks and disable or block the CWD and LIST commands where feasible.
- Run the FTP service under a low-privilege account and isolate it from sensitive data and systems.
- Place the service behind a filtering proxy or firewall that rejects oversized command arguments.
Detection
- Monitor FTP logs for abnormally long CWD or LIST command arguments and for repeated server crashes or restarts.
- Alert on process crashes of the GuildFTPd service and correlate them with inbound FTP command traffic.
- Inspect network traffic for oversized FTP command lines targeting CWD or LIST.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4572 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4572), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.