---
cve: "CVE-2010-4221"
severity: "LOW"
cvss: 3.1
epss: "91.3%"
vendor: "n/a"
kev: false
exploited: false
published: "2010-11-09 21:00:06"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T13:56:51+02:00"
---

# CVE-2010-4221

> 3.1 LOW

## Beschreibung

Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.

## Exploit-Evidenz

- [EDB-16851 — ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)](https://www.exploit-db.com/exploits/16851) ✅
- [EDB-16878 — ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)](https://www.exploit-db.com/exploits/16878) ✅
- [EDB-15449 — ProFTPd IAC 1.3.x - Remote Command Execution](https://www.exploit-db.com/exploits/15449) ✅

## Referenzen

- <http://www.proftpd.org/docs/NEWS-1.3.3c>
- <http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050687.html>
- <http://www.zerodayinitiative.com/advisories/ZDI-10-229/>
- <http://secunia.com/advisories/42217>
- <http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050703.html>
- <http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050726.html>
- <http://www.vupen.com/english/advisories/2010/2941>
- <http://www.vupen.com/english/advisories/2010/2962>
- <http://secunia.com/advisories/42052>
- <http://bugs.proftpd.org/show_bug.cgi?id=3521>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2010:227>
- <http://www.securityfocus.com/bid/44562>
- <http://www.vupen.com/english/advisories/2010/2959>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2010-4221) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
