CVE
- Id
- 2149
- CVE No.
- CVE-2000-0573
- Status
- Entry
- Description
- The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
7448 | 2149 | CVE-2000-0573 | BUGTRAQ:20000622 WuFTPD: Providing *remote* root since at least1994 | View |
7449 | 2149 | CVE-2000-0573 | URL:http://marc.info/?l=bugtraq&m=96171893218000&w=2 | View |
7450 | 2149 | CVE-2000-0573 | BUGTRAQ:20000623 WUFTPD 2.6.0 remote root exploit | View |
7451 | 2149 | CVE-2000-0573 | URL:http://marc.info/?l=bugtraq&m=96179429114160&w=2 | View |
7452 | 2149 | CVE-2000-0573 | BUGTRAQ:20000707 New Released Version of the WuFTPD Sploit | View |
7453 | 2149 | CVE-2000-0573 | URL:http://marc.info/?l=bugtraq&m=96299933720862&w=2 | View |
7454 | 2149 | CVE-2000-0573 | BUGTRAQ:20000623 ftpd: the advisory version | View |
7455 | 2149 | CVE-2000-0573 | URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000623091822.3321.qmail@fiver.freemessage.com | View |
7456 | 2149 | CVE-2000-0573 | AUSCERT:AA-2000.02 | View |
7457 | 2149 | CVE-2000-0573 | URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02 | View |
7458 | 2149 | CVE-2000-0573 | CERT:CA-2000-13 | View |
7459 | 2149 | CVE-2000-0573 | URL:http://www.cert.org/advisories/CA-2000-13.html | View |
7460 | 2149 | CVE-2000-0573 | DEBIAN:20000623 | View |
7461 | 2149 | CVE-2000-0573 | CALDERA:CSSA-2000-020.0 | View |
7462 | 2149 | CVE-2000-0573 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt | View |
7463 | 2149 | CVE-2000-0573 | REDHAT:RHSA-2000:039 | View |
7464 | 2149 | CVE-2000-0573 | URL:http://www.redhat.com/support/errata/RHSA-2000-039.html | View |
7465 | 2149 | CVE-2000-0573 | BUGTRAQ:20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release) | View |
7466 | 2149 | CVE-2000-0573 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html | View |
7467 | 2149 | CVE-2000-0573 | BUGTRAQ:20000702 [Security Announce] wu-ftpd update | View |
7468 | 2149 | CVE-2000-0573 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html | View |
7469 | 2149 | CVE-2000-0573 | BUGTRAQ:20000929 [slackware-security] wuftpd vulnerability - Slackware 4.0, 7.0, 7.1, -current | View |
7470 | 2149 | CVE-2000-0573 | FREEBSD:FreeBSD-SA-00:29 | View |
7471 | 2149 | CVE-2000-0573 | URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1 | View |
7472 | 2149 | CVE-2000-0573 | NETBSD:NetBSD-SA2000-009 | View |
7473 | 2149 | CVE-2000-0573 | URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc | View |
7474 | 2149 | CVE-2000-0573 | XF:wuftp-format-string-stack-overwrite | View |
7475 | 2149 | CVE-2000-0573 | BID:1387 | View |
7476 | 2149 | CVE-2000-0573 | URL:http://www.securityfocus.com/bid/1387 | View |
7477 | 2149 | CVE-2000-0573 | XF:wuftp-format-string-stack-overwrite(4773) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
64264 | JVNDB-2000-000044 | WU-FTPD におけるフォーマットストリングの脆弱性 | WU-FTPD には、FTP の SITE EXEC コマンドの引数として "%" 文字を指定した場合、wu-ftpd はこれを C 言語 の printf() 関数等で使用される フォーマットストリング (書式変換指定) として扱ってしまう脆弱性が存在します。 | CVE-2000-0573 | 2149 | 10 | http://jvndb.jvn.jp/ja/contents/2000/JVNDB-2000-000044.html | View |