VulnerabilityModified
CVE-2001-0053
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
HIGH 10.0EPSS 17.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 17.93% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- david madore/ftpd-bsd · netbsd/netbsd · openbsd/openbsd
- Source
- cve@mitre.org
References
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.htmlPatch
- http://www.openbsd.org/advisories/ftpd_replydirname.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2124Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5776
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.htmlPatch
- http://www.openbsd.org/advisories/ftpd_replydirname.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2124Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5776
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.