VulnerabilityAnalyzed
CVE-2012-10023
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0.
MEDIUM 6.9EPSS 1.73%
Does this matter?
Lower severity and a low EPSS score (1.73%). Track it; it rarely justifies an emergency change on its own.
Description
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121
- Affected
- freefloat/freefloat ftp server
- Source
- disclosure@vulncheck.com
References
- https://my.saintcorporation.com/cgi-bin/exploit_info/freefloat_ftp_server_user_cmdThird Party Advisory
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/freefloatftp_user.rbExploit
- https://web.archive.org/web/20101208040029/http://secunia.com/advisories/42465/Third Party Advisory
- https://web.archive.org/web/20101213050627/http://www.freefloat.com/sv/about-/about-.phpProduct
- https://www.exploit-db.com/exploits/15689Exploit
- https://www.exploit-db.com/exploits/23243Exploit
- https://www.vulncheck.com/advisories/freefloat-ftp-server-user-command-buffer-overflowThird Party Advisory
- https://www.exploit-db.com/exploits/23243Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.