7.5
CVSSv2

CVE-2001-0489

Published: 27/06/2001 Updated: 03/05/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in gftp before 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.

Vulnerable Product Search on Vulmon Subscribe to Product

gftp gftp

Vendor Advisories

The gftp package as distributed with Debian GNU/Linux 22 has a problem in its logging code: it logged data received from the network but it did not protect itself from printf format attacks An attacker can use this by making an FTP server return special responses that exploit this This has been fixed in version 206a-31, and we recommend that ...