CVE-2006-6652

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

Date published : 2006-12-19

http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html

http://www.securityfocus.com/bid/21377