CVE-2025-11947 | bftpd up to 6.2 Configuration File options.c expand_groups heap-based overflow (EUVD-2025-35011 / CNNVD-202510-2555)
A vulnerability described as problematic has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing manipulation can lead to heap-based buffer overflow.
This vulnerability is handled as CVE-2025-11947. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.