A vulnerabilty has been discovered in Archimede's glftpd which may allow an unauthorized user to overwrite sensitive data. It is possible for an attacker to overwrite sensitive FTP files by sending messages to maliciously constructed usernames. Files influenced by this issue would be limited to those contained within the chrooted environment. By exploiting this issue an attacker would be able to overwrite an arbitrary file with formatted message text.
A vulnerabilty has been discovered in Archimede's glftpd which may allow an unauthorized user to overwrite sensitive data. It is possible for an attacker to overwrite sensitive FTP files by sending messages to maliciously constructed usernames. Files influenced by this issue would be limited to those contained within the chrooted environment. By exploiting this issue an attacker would be able to overwrite an arbitrary file with formatted message text.