积极预防 及时发现
快速响应 力保恢复
wu-ftpd 2.6.1及其早期版本中存在格式化字符串漏洞,当在调试模式下运行时,允许远程攻击者通...
发布时间:2001-03-26 信息来源:管理员

CNCVE编号:CNCVE-20010187 CVE编号:CVE-2001-0187 安全级别:高 漏洞中文描述: wu-ftpd 2.6.1及其早期版本中存在格式化字符串漏洞,当在调试模式下运行时,允许远程攻击者通过变形的参数(这些参数记录在PASV端口分配中)来执行任意命令。 漏洞英文描述: Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment. 漏洞参考: BID:2296 XF:wuftp-debug-format-string DEBIAN:DSA-016 系统类型:其他 漏洞类型:异常处理错误