VulnerabilityModified
CVE-2011-5164
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
HIGH 9.3EPSS 28.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 28.58% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- vandyke/absoluteftp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/46781Vendor Advisory
- http://www.exploit-db.com/exploits/18102Exploit
- http://www.osvdb.org/77105
- http://www.saintcorporation.com/cgi-bin/exploit_info/vandyke_absoluteftp_list_client_overflow
- http://www.securityfocus.com/bid/50614
- http://secunia.com/advisories/46781Vendor Advisory
- http://www.exploit-db.com/exploits/18102Exploit
- http://www.osvdb.org/77105
- http://www.saintcorporation.com/cgi-bin/exploit_info/vandyke_absoluteftp_list_client_overflow
- http://www.securityfocus.com/bid/50614
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.