[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0247Date: (C)2001-06-18   (M)2023-12-22


Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.nai.com/research/covert/advisories/048.asp
20010802-01-P
BID-2548
CA-2001-07
FreeBSD-SA-01:33
NetBSD-SA2000-018
ftp-glob-expansion(6332)

CPE    47
cpe:/o:sgi:irix:6.5.3
cpe:/o:openbsd:openbsd:2.3
cpe:/o:sgi:irix:6.5.5
cpe:/o:openbsd:openbsd:2.5
...

© SecPod Technologies