PT-2001-1994 · Cesar · Cesarftp
Publicado
2001-11-22
·
Atualizado
2008-09-10
·
CVE-2001-0826
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CesarFTPD version 0.98b
Description
The issue allows remote attackers to execute arbitrary commands due to buffer overflows. This can be achieved by providing long arguments to various commands, including
HELP, USER, PASS, PORT, DELE, REST, RMD, or MKD.Recommendations
For CesarFTPD version 0.98b, consider restricting access to these commands or limiting the length of arguments passed to them as a temporary mitigation measure until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cesarftp