积极预防 及时发现
快速响应 力保恢复
当使用一个畸形工作目录(cwd)时,ProFTPD 1.2.0rc2 中的格式化字符串漏洞可能允许攻...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010318 CVE编号:CVE-2001-0318 安全级别:高 漏洞中文描述: 当使用一个畸形工作目录(cwd)时,ProFTPD 1.2.0rc2 中的格式化字符串漏洞可能允许攻击者通过关闭FTP服务器来执行任意命令。 漏洞英文描述: Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd). 漏洞参考: BUGTRAQ:20010110 proftpd 1.2.0rc2 -- example of bad coding | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916525715657&w=2 | BUGTRAQ:20010206 Response to ProFTPD issues | URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0117.html 系统类型:其他 漏洞类型:设计错误