5
CVSSv2

CVE-2003-0853

Published: 17/11/2003 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu fileutils 4.0

washington university wu-ftpd 2.4.2 beta18

washington university wu-ftpd 2.4.2 beta18 vr14

washington university wu-ftpd 2.5.0

washington university wu-ftpd 2.4.2 vr17

washington university wu-ftpd 2.4.2 beta18 vr9

gnu fileutils 4.0.36

washington university wu-ftpd 2.4.1

gnu fileutils 4.1

gnu fileutils 4.1.7

washington university wu-ftpd 2.4.2 vr16

washington university wu-ftpd 2.6.2

washington university wu-ftpd 2.6.0

washington university wu-ftpd 2.4.2 beta18 vr11

washington university wu-ftpd 2.4.2 beta18 vr6

gnu fileutils 4.1.6

washington university wu-ftpd 2.4.2 beta18 vr4

washington university wu-ftpd 2.4.2 beta18 vr12

washington university wu-ftpd 2.4.2 beta18 vr5

washington university wu-ftpd 2.4.2 beta18 vr13

washington university wu-ftpd 2.4.2 beta18 vr10

washington university wu-ftpd 2.4.2 beta18 vr15

washington university wu-ftpd 2.6.1

washington university wu-ftpd 2.4.2 beta2

washington university wu-ftpd 2.4.2 beta18 vr7

washington university wu-ftpd 2.4.2 beta18 vr8

Exploits

source: wwwsecurityfocuscom/bid/8875/info Coreutils 'ls' has been reported prone to an integer overflow vulnerability The issue reportedly presents itself when handling width and column display command line arguments It has been reported that excessive values passed as a width argument to 'ls' may cause an internal integer value to be m ...