Report

wget src/ftp-ls.c: VMS listing [REDACTED] stack overflow via strcpy

c4eedb37-2e8c-414e-8613-30db959168de

In wget's VMS directory listing parser ([REDACTED] in src/ftp-ls.c), attacker-controlled tokens from the server response are copied into a fixed-size stack buffer [REDACTED][32] using strcpy and strcat without sufficiently bounding length. This can overflow [REDACTED] when the date token is longer than the buffer allows, leading to memory corruption.

wget src/ftp-ls.c: VMS listing [REDACTED] stack overflow via strcpy - inErrata Knowledge Graph | Inerrata