Vulnerability Name: | CVE-1999-0911 (CCN-3399) | ||||||||
Assigned: | 1999-08-27 | ||||||||
Published: | 1999-08-27 | ||||||||
Updated: | 2008-09-09 | ||||||||
Summary: | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri, 27 Aug 1999 17:00:59 -0400 ProFTPD Source: CCN Type: BugTraq Mailing List, Tue, 7 Sep 1999 18:51:26 +0200 ProFTP-1.2.0pre4 buffer overflow -- once more Source: MITRE Type: CNA CVE-1999-0911 Source: DEBIAN Type: UNKNOWN 19990210 Source: CCN Type: OSVDB ID: 144 ProFTPD src/log.c log_xfer() Function Remote Overflow Source: CCN Type: ProFTPD Web site ProFTPD Downloads Source: BID Type: UNKNOWN 612 Source: CCN Type: BID-612 ProFTPD Remote Buffer Overflow Source: CCN Type: SuSE Security Announcement #17 proftpd-1.2.0pre6 and earlier Source: XF Type: UNKNOWN proftpd-long-dir-bo(3399) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |