SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0466

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to…

CRITICAL 9.8EPSS 78.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 78.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
78.11% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-193
Affected
redhat/wu ftpd · wuftpd/wu-ftpd · apple/mac os x · apple/mac os x server · freebsd/freebsd · netbsd/netbsd · openbsd/openbsd · sun/solaris
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.