CVE-2000-0574

OpenBSD ftpd - Remote Code Execution via Format String in setproctitle

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0574. PoCs published by Teso.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in OpenBSD's ftp daemon (CVE-2000-0574) by sending a maliciously crafted MKD command with shellcode to achieve remote code execution. The shellcode is designed to spawn a shell, and the exploit manipulates the return address to redirect execution flow.

Description

FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Teso · clocalbsd
https://www.exploit-db.com/exploits/396

This exploit targets a buffer overflow vulnerability in OpenBSD's ftp daemon (CVE-2000-0574) by sending a maliciously crafted MKD command with shellcode to achieve remote code execution. The shellcode is designed to spawn a shell, and the exploit manipulates the return address to redirect execution flow.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenBSD ftp daemon (version not explicitly specified)
Auth required
Prerequisites: Network access to the target FTP service · Valid FTP credentials (anonymous or otherwise)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1425
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-07/0121.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1438
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2000-13.html

Scores

EPSS 0.5887
EPSS Percentile 99.0%

Details

Status published
Products (20)
openbsd/ftpd 5.51
openbsd/ftpd 5.60
washington_university/wu-ftpd 2.4.2_beta1
washington_university/wu-ftpd 2.4.2_beta18
washington_university/wu-ftpd 2.4.2_beta18_vr4
washington_university/wu-ftpd 2.4.2_beta18_vr5
washington_university/wu-ftpd 2.4.2_beta18_vr6
washington_university/wu-ftpd 2.4.2_beta18_vr7
washington_university/wu-ftpd 2.4.2_beta18_vr8
washington_university/wu-ftpd 2.4.2_beta18_vr9
... and 10 more
Published Jul 07, 2000
Tracked Since Feb 18, 2026