CVE-2011-5164
high · 9.3Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
9.3
CVSS
28.6%
EPSS (exploit prob.)
98th
EPSS percentile
2012-09-15
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vandyke | absoluteftp | 1.9.6 |
| vandyke | absoluteftp | 2.0.3 |
| vandyke | absoluteftp | 2.0.4 |
| vandyke | absoluteftp | 2.0.5 |
| vandyke | absoluteftp | 2.2.1 |
| vandyke | absoluteftp | 2.2.2 |
| vandyke | absoluteftp | 2.2.3 |
| vandyke | absoluteftp | 2.2.4 |
| vandyke | absoluteftp | 2.2.5 |
| vandyke | absoluteftp | 2.2.6 |
| vandyke | absoluteftp | 2.2.7 |
| vandyke | absoluteftp | 2.2.8 |
| vandyke | absoluteftp | 2.2.9 |
| vandyke | absoluteftp | 2.2.10 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/46781
- http://www.exploit-db.com/exploits/18102
- http://www.osvdb.org/77105
- http://www.saintcorporation.com/cgi-bin/exploit_info/vandyke_absoluteftp_list_client_overflow
- http://www.securityfocus.com/bid/50614
- http://secunia.com/advisories/46781
- http://www.exploit-db.com/exploits/18102
- http://www.osvdb.org/77105
- http://www.saintcorporation.com/cgi-bin/exploit_info/vandyke_absoluteftp_list_client_overflow
- http://www.securityfocus.com/bid/50614
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-5164