7.5
CVSSv2

CVE-2014-1693

Published: 08/12/2014 Updated: 16/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent malicious users to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

erlang erlang\\/otp r15b03

Vendor Advisories

Debian Bug report logs - #738132 CVE-2014-1693 Package: src:erlang; Maintainer for src:erlang is Debian Erlang Packagers <pkg-erlang-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 7 Feb 2014 22:57:01 UTC Severity: important Tags: security Fixed in versions erlang/1:16b ...
Several security issues were fixed in Erlang ...