LiveActive security incident?Get immediate response
CVE Record

CVE-2019-25611: MiniFtp parseconf_load_setting Buffer Overflow via Configuration

MiniFtp contains a buffer overflow vulnerability in the parseconf_load_setting function that allows local attackers to execute arbitrary code by supplying oversized configuration values. Attackers can craft a miniftpd.conf file with values exceeding 128 bytes to overflow stack buffers and overwrite the return address, enabling code execution with root privileges.

HighCVSS 8.6Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

MiniFtp has a configuration-parsing buffer overflow. If an attacker can supply an oversized value in the MiniFtp configuration file, the service may execute attacker-controlled code, potentially with root privileges. This is mainly a local or configuration-control risk, not a remote network attack based on the provided sources.

Executive priority

Treat as high priority for environments using MiniFtp, especially shared Linux hosts, appliances, or systems where configuration files may be modified by non-administrators. If MiniFtp is not deployed, business urgency is low. There is public exploit information, but no sourced evidence of active exploitation.

Technical view

CVE-2019-25611 affects skyqinsc MiniFtp. The parseconf_load_setting function uses fixed stack buffers and can be overflowed by configuration values exceeding 128 bytes. The issue is classified as CWE-787 and scored CVSS 4.0 8.6. Sources describe arbitrary code execution through crafted miniftpd.conf content.

Likely exposure

Organizations are exposed if they run MiniFtp and allow untrusted users, automation, packages, or deployment pipelines to write or replace miniftpd.conf. Exposure is higher where MiniFtp runs as root. The source bundle lists all versions as affected, but no fixed version is identified.

Exploitation context

A public ExploitDB reference exists, indicating exploit information is public. The provided sources do not show CISA KEV listing or active exploitation. The attack requires local ability to provide or influence the configuration file rather than unauthenticated remote FTP access.

Researcher notes

The key evidence is local configuration-driven stack overflow in parseconf_load_setting. The advisory states oversized configuration values can overwrite the return address. No patch, affected release boundary, or maintainer remediation is provided in the source bundle, so validation should focus on deployment presence, config control, and privilege context.

Mitigation direction

  • Inventory systems running skyqinsc MiniFtp.
  • Restrict write access to miniftpd.conf and its parent directories.
  • Run MiniFtp with least privileges where operationally possible.
  • Replace MiniFtp if no vendor fix is available.
  • Monitor the vendor repository and advisories for remediation guidance.

Validation and detection

  • Confirm whether MiniFtp is installed or deployed.
  • Identify the active miniftpd.conf path and ownership.
  • Review file permissions for unauthorized write access.
  • Check service account privileges, especially root execution.
  • Compare deployed code against vendor repository updates.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-787: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2019-25611 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 4.0HighCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NPrimary CVE score

Vulnerability scoring details

Base CVSS 4.0 score

8.6High
CVSS 4.0 vector shape for CVE-2019-25611Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
skyqinscMiniFtp*Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-787 · source CWE mapping

Out-of-bounds Write

Out-of-bounds Write represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.