FreeBSD Security Advisory FreeBSD-SA-03:08.realpath – An off-by-one error exists in a portion of realpath(3) that computes the length of a resolved pathname. As a result, applications making use of realpath(3) may be vulnerable to denial of service attacks, remote code execution, and privilege escalation. A staggering amount of applications make use of this functionality, including but not limited to, sftp-server and lukemftpd.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31484/FreeBSD-SA-03%3A08.realpath
Source: https://packetstormsecurity.com/files/31484/FreeBSD-Security-Advisory-2003.8.html

