Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6171

Опубликовано: 30 нояб. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:proftpd_project:proftpd:*:*:*:*:*:*:*:*
Версия до 1.3.0a (включая)

EPSS

Процентиль: 87%
0.03858
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

debian
почти 19 лет назад

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit ...

github
больше 3 лет назад

** DISPUTED ** ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability.

fstec
около 19 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 87%
0.03858
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other