Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value. This vulnerability is addressed in the following product update:
ProFTPD Project, ProFTPD, 1.3.1rc1
Publication date: Thu, 18 Oct 2018 02:49:00 +0000