10
CVSSv2

CVE-2004-0185

Published: 15/03/2004 Updated: 14/02/2024
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.

Vulnerable Product Search on Vulmon Subscribe to Product

washington university wu-ftpd 2.6.2

Vendor Advisories

Two vulnerabilities were discovered in wu-ftpd: CAN-2004-0148 Glenn Stewart discovered that users could bypass the directory access restrictions imposed by the restricted-gid option by changing the permissions on their home directory On a subsequent login, when access to the user's home directory was denied, wu-ftpd would fall back to the ro ...