5
CVSSv2

CVE-2000-0574

Published: 07/07/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote malicious users to cause a denial of service or execute arbitrary commands.

Vulnerable Product Search on Vulmon Subscribe to Product

washington university wu-ftpd 2.4.2 beta18

washington university wu-ftpd 2.4.2 beta18 vr14

washington university wu-ftpd 2.4.2 vr17

washington university wu-ftpd 2.4.2 beta18 vr9

washington university wu-ftpd 2.5

washington university wu-ftpd 2.4.2 vr16

washington university wu-ftpd 2.4.2 beta18 vr11

washington university wu-ftpd 2.4.2 beta18 vr6

washington university wu-ftpd 2.4.2 beta1

openbsd ftpd 5.51

washington university wu-ftpd 2.4.2 beta18 vr4

washington university wu-ftpd 2.6

washington university wu-ftpd 2.4.2 beta18 vr12

washington university wu-ftpd 2.4.2 beta18 vr5

washington university wu-ftpd 2.4.2 beta18 vr13

washington university wu-ftpd 2.4.2 beta18 vr10

washington university wu-ftpd 2.4.2 beta18 vr15

washington university wu-ftpd 2.4.2 beta18 vr7

openbsd ftpd 5.60

washington university wu-ftpd 2.4.2 beta18 vr8

Exploits

/* 7350-crocodile - x86/OpenBSD ftp exploit * * by lorian and scut / TESO=20 * * * TESO CONFIDENTIAL - SOURCE MATERIALS * * This is unpublished proprietary source code of TESO Security * * The contents of these coded instructions, statements and computer * programs may not be disclosed to third parties, copied or duplicated in * any fo ...