CVE
- Id
- 3117
- CVE No.
- CVE-2001-0296
- Status
- Candidate
- Description
- Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.
- Phase
- Proposed (20010404)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese | RECAST(1) Prosser | REVIEWING(1) Bishop
- Comments
- Frech> XF:wftpd-pro-cwd-bo(6184) | Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one. It looks like Can-2001-0296 may be a continuation of CVE 1999-0950. Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950). Just managed to change the code so it requires more characters to overflow the buffer. I haven"t tested this, but just from the available documentation, these problems look like a continuation of the early one.