wu-ftpd versions 2.5.0 to 2.6.2 have been found to be susceptible to an off-by-one bug in fb_realpath(). A local or remote attacker could exploit this vulnerability to gain root privileges on a vulnerable system.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31479/isec-0011-wu-ftpd.txt
Source: https://packetstormsecurity.com/files/31479/isec-0011-wu-ftpd.txt.html

