CVE-2003-0831
high · 9ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.
9
CVSS
58.4%
EPSS (exploit prob.)
99th
EPSS percentile
2003-11-17
Published
AV:N/AC:L/Au:S/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| proftpd_project | proftpd | 1.2.7 |
| proftpd_project | proftpd | 1.2.7_rc1 |
| proftpd_project | proftpd | 1.2.7_rc2 |
| proftpd_project | proftpd | 1.2.7_rc3 |
| proftpd_project | proftpd | 1.2.8 |
| proftpd_project | proftpd | 1.2.8_rc1 |
| proftpd_project | proftpd | 1.2.8_rc2 |
| proftpd_project | proftpd | 1.2.9_rc1 |
| proftpd_project | proftpd | 1.2.9_rc2 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html
- http://marc.info/?l=bugtraq&m=106441655617816&w=2
- http://marc.info/?l=bugtraq&m=106606885611269&w=2
- http://secunia.com/advisories/9829
- http://www.kb.cert.org/vuls/id/405348
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:095
- http://xforce.iss.net/xforce/alerts/id/154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12200
- https://www.exploit-db.com/exploits/107/
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html
- http://marc.info/?l=bugtraq&m=106441655617816&w=2
- http://marc.info/?l=bugtraq&m=106606885611269&w=2
- http://secunia.com/advisories/9829
- http://www.kb.cert.org/vuls/id/405348
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:095
- http://xforce.iss.net/xforce/alerts/id/154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12200
- https://www.exploit-db.com/exploits/107/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0831