Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0466

Опубликовано: 27 авг. 2003
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Высокий

Описание

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:wu_ftpd:2.6.1-16:*:*:*:*:*:*:*
cpe:2.3:a:wuftpd:wu-ftpd:*:*:*:*:*:*:*:*
Версия от 2.5.0 (включая) до 2.6.2 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:apple:mac_os_x:10.2.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.2.6:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 5.0 (включая)
cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*
Версия от 1.5 (включая) до 1.6.1 (включая)
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 3.3 (включая)
cpe:2.3:o:sun:solaris:9.0:*:*:*:*:sparc:*:*

EPSS

Процентиль: 100%
0.78115
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-193

Связанные уязвимости

redhat
около 23 лет назад

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

CVSS3: 9.8
debian
почти 23 года назад

Off-by-one error in the fb_realpath() function, as derived from the re ...

github
около 4 лет назад

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

fstec
почти 23 года назад

Уязвимость операционной системы openSUSE, позволяющая злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 100%
0.78115
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-193