Arcane Software’s Vermillion FTP Daemon (vftpd) versions...
Critical severity
Unreviewed
Published
Aug 21, 2025
to the GitHub Advisory Database
•
Updated Aug 21, 2025
Description
Published by the National Vulnerability Database
Aug 21, 2025
Published to the GitHub Advisory Database
Aug 21, 2025
Last updated
Aug 21, 2025
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.
References