Last Modified: Sept. 9, 2008
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.
Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: Complete
Integrity Impact: Complete
Availability Impact: Complete
Base Score: 10.0
Exploitability Score: 10.0
Impact Score: 10.0
CVSS V2: AV:N/AC:L/Au:N/C:C/I:C/A:C
NVD-CWE-Other
Condition | Configuration | |
---|---|---|
OR | ||
OR | ||
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr14:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr17:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr9:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.5:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr16:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:beroftpd:beroftpd:1.3.4:*:*:*:*:*:*:* Part: a Vendor: beroftpd | Alle Schwachstellen für beroftpd | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr11:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr6:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr4:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr13:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr15:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr10:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr12:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr5:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr8:*:*:*:*:*:*:* Part: a Vendor: washington_university | Alle Schwachstellen für washington_university | |
cpe:2.3:a:beroftpd:beroftpd:1.3.2:*:*:*:*:*:*:* Part: a Vendor: beroftpd | Alle Schwachstellen für beroftpd | |
cpe:2.3:a:beroftpd:beroftpd:1.3.3:*:*:*:*:*:*:* Part: a Vendor: beroftpd | Alle Schwachstellen für beroftpd |
<?xml version="1.0" ?> <set operator="and"> <set operator="or"> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr14:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr17:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr9:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.5:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr16:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:beroftpd:beroftpd:1.3.4:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr11:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr6:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr4:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr13:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr15:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr10:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr12:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr5:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr8:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:beroftpd:beroftpd:1.3.2:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:beroftpd:beroftpd:1.3.3:*:*:*:*:*:*:*"/> </set> <prop key="program_influence" value="input"/> <prop key="range" value="remote"/> </set>
<?xml version="1.0" ?> <set operator="and"> <prop key="target" value="host"/> <set operator="or"> <prop key="program_influence" value="input"/> <prop key="program_influence" value="output"/> <prop key="program_influence" value="existence"/> </set> <prop key="data" value="any"/> <set operator="or"> <prop key="data_influence" value="read"/> <prop key="data_influence" value="write"/> <prop key="data_influence" value="delete"/> </set> <set operator="or"> <prop key="range" value="remote"/> <prop key="range" value="local"/> </set> </set>