Record summary

CVE-2001-0247 has a selected CVSS score of 10.0; EIP currently links 3 catalogued exploits.

Description

Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBFreeBSD 2.2-4.2 / NetBSD 1.2-4.5 / OpenBSD 2.x - FTPd 'glob()' Remote Buffer OverflowExploitDB exploitby fish stiqzNot analyzed1 file
ExploitDB

PoC details
ExploitDBFreeBSD 4.2-stable - FTPd 'glob()' Remote Buffer OverflowExploitDB exploitby Elias LevyNot analyzed1 file
ExploitDB

PoC details
ExploitDBOpenBSD 2.x < 2.8 FTPd - 'glob()' Remote Buffer OverflowExploitDB exploitby Elias LevyNot analyzed1 file
ExploitDB

PoC details

References

6