PT-2001-1994 · Cesar · Cesarftp

Published

2001-11-22

·

Updated

2008-09-10

·

CVE-2001-0826

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CesarFTPD version 0.98b
Description The issue allows remote attackers to execute arbitrary commands due to buffer overflows. This can be achieved by providing long arguments to various commands, including HELP, USER, PASS, PORT, DELE, REST, RMD, or MKD.
Recommendations For CesarFTPD version 0.98b, consider restricting access to these commands or limiting the length of arguments passed to them as a temporary mitigation measure until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0826

Affected Products

Cesarftp