20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSDmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html CVE-2001-0053
BSD ftpd 0.3.2 - Single Byte Buffer Overflow
Record summary
CVE-2001-0053 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBBSD ftpd 0.3.2 - Single Byte Buffer OverflowExploitDB exploitby ScrippieNot analyzed1 file
ExploitDBOpenBSD ftpd 2.6/2.7 - Remote OverflowExploitDB exploitby ScrippieNot analyzed1 file
References
520001218Vendor advisory
http://www.openbsd.org/advisories/ftpd_replydirname.txt 2124vdb entry
http://www.securityfocus.com/bid/2124 bsd-ftpd-replydirname-bo(5776)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5776 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0053