10
CVSSv2

CVE-2001-0187

Published: 26/03/2001 Updated: 10/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in wu-ftp 2.6.1 and previous versions, when running with debug mode enabled, allows remote malicious users to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

Vulnerable Product Search on Vulmon Subscribe to Product

washington university wu-ftpd 2.4.2_beta18_vr12

washington university wu-ftpd 2.4.2_beta18_vr13

washington university wu-ftpd 2.4.2_beta18_vr8

washington university wu-ftpd 2.4.2_beta18_vr9

washington university wu-ftpd 2.4.1

washington university wu-ftpd 2.4.2_beta18

washington university wu-ftpd 2.4.2_beta18_vr4

washington university wu-ftpd 2.4.2_beta18_vr5

washington university wu-ftpd 2.4.2_vr17

washington university wu-ftpd 2.5

washington university wu-ftpd 2.4.2_beta18_vr10

washington university wu-ftpd 2.4.2_beta18_vr11

washington university wu-ftpd 2.4.2_beta18_vr6

washington university wu-ftpd 2.4.2_beta18_vr7

washington university wu-ftpd 2.6

washington university wu-ftpd 2.4.2_beta18_vr14

washington university wu-ftpd 2.4.2_beta18_vr15

washington university wu-ftpd 2.4.2_beta9

washington university wu-ftpd 2.4.2_vr16

Vendor Advisories

Security people at WireX have noticed a temp file creation bug and the WU-FTPD development team has found a possible format string bug in wu-ftpd Both could be remotely exploited, though no such exploit exists currently We recommend you upgrade your wu-ftpd package immediately ...

Exploits

source: wwwsecurityfocuscom/bid/2296/info Wu-ftpd is a widely used unix ftp server It contains a format string vulnerability that may be exploitable under certain (perhaps 'extreme') circumstances When running in debug mode, Wu-ftpd logs user activity to syslog in an insecure manner An attacker with control over the server's hostname ...