CVE-2003-0853

GNU fileutils - Denial of Service and Remote Code Execution via Large -w Value

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0853. PoCs published by druid.

AI-analyzed exploit summary This exploit targets an integer overflow vulnerability in the 'ls' utility (CVE-2003-0853) by passing excessive width arguments, causing a denial of service. It automates the attack via FTP against a target system running wu-ftpd 2.6.2.

Description

An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.

Exploits (1)

exploitdb WORKING POC VERIFIED
by druid · perldoslinux
https://www.exploit-db.com/exploits/23274

This exploit targets an integer overflow vulnerability in the 'ls' utility (CVE-2003-0853) by passing excessive width arguments, causing a denial of service. It automates the attack via FTP against a target system running wu-ftpd 2.6.2.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Coreutils 'ls' (via wu-ftpd 2.6.2)
Auth required
Prerequisites: FTP access to the target system · wu-ftpd 2.6.2 or vulnerable 'ls' utility
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-309.html
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000771
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000768
Various Sources vendor-advisory x_refsource_turbo
http://www.turbolinux.com/security/TLSA-2003-60.txt
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-310.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8875
Third Party Advisory, VDB Entry vendor-advisory x_refsource_immunix
http://www.securityfocus.com/advisories/6014
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17069
Various Sources x_refsource_misc
http://www.guninski.com/binls.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/10126
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2003:106

Scores

EPSS 0.1044
EPSS Percentile 95.2%

Details

Status published
Products (26)
gnu/fileutils 4.0
gnu/fileutils 4.0.36
gnu/fileutils 4.1
gnu/fileutils 4.1.6
gnu/fileutils 4.1.7
washington_university/wu-ftpd 2.4.1
washington_university/wu-ftpd 2.4.2_beta2
washington_university/wu-ftpd 2.4.2_beta18
washington_university/wu-ftpd 2.4.2_beta18_vr4
washington_university/wu-ftpd 2.4.2_beta18_vr5
... and 16 more
Published Nov 17, 2003
Tracked Since Feb 18, 2026