9
CVSSv2

CVE-2006-6652

Published: 20/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 910
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current prior to 20050914, NetBSD 2.* and 3.* prior to 20061203, and Apple Mac OS X prior to 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.0.2

apple mac os x 10.0.3

apple mac os x 10.0.4

apple mac os x 10.1

apple mac os x 10.2.8

apple mac os x 10.3

apple mac os x 10.3.1

apple mac os x 10.3.2

apple mac os x 10.4.6

apple mac os x 10.4.7

apple mac os x 10.4.8

apple mac os x 10.4.9

apple mac os x 10.1.5

apple mac os x 10.2

apple mac os x 10.2.1

apple mac os x 10.2.2

apple mac os x 10.2.3

apple mac os x 10.3.7

apple mac os x 10.3.8

apple mac os x 10.3.9

apple mac os x 10.4

apple mac os x 10.0

apple mac os x 10.1.2

apple mac os x 10.1.4

apple mac os x 10.2.5

apple mac os x 10.2.7

apple mac os x 10.3.3

apple mac os x 10.3.5

apple mac os x 10.4.2

apple mac os x 10.4.4

apple mac os x 10.0.1

apple mac os x 10.1.1

apple mac os x 10.1.3

apple mac os x 10.2.4

apple mac os x 10.2.6

apple mac os x 10.3.4

apple mac os x 10.3.6

apple mac os x 10.4.1

apple mac os x 10.4.3

apple mac os x 10.4.5

apple mac os x 10.4.10

netbsd netbsd 3.0

netbsd netbsd 3.1

netbsd netbsd 2.1

netbsd netbsd 2.0

Exploits

source: wwwsecurityfocuscom/bid/21377/info NetBSD ftpd and tnftpd are prone to a remote buffer-overflow vulnerability This issue is due to an off-by-one error; it allows attackers to corrupt memory Remote attackers may execute arbitrary machine code in the context of the user running the affected application Failed attempts will likel ...
#!perl # $$$ NetBSD ftpd and ports *Remote ROOOOOT $HOLE$* $$$ # # About # # tnftpd is a port of the NetBSD FTP server to other systems # It offers many enhancements over the traditional BSD ftpd, # including per-class configuration directives via ftpdconf(5), # RFC 2389 and draft-ietf-ftpext-mlst-11 support, IPv6, # transfer rate throttling, and ...