Vulnerabilities > CVE-2001-0187 - Unspecified vulnerability in Washington University Wu-Ftpd

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
washington-university
critical
nessus
exploit available

Summary

Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

Exploit-Db

descriptionWu-Ftpd 2.4.2/2.5/2.6 Debug Mode Client Hostname Format String Vulnerability. CVE-2001-0187. Remote exploit for unix platform
idEDB-ID:20594
last seen2016-02-02
modified2001-01-23
published2001-01-23
reporterWu-ftpd team
sourcehttps://www.exploit-db.com/download/20594/
titleWu-Ftpd 2.4.2/2.5/2.6 - Debug Mode Client Hostname Format String Vulnerability

Nessus

  • NASL familyFTP
    NASL idWU_FTPD_PASV_FORMAT_STRING.NASL
    descriptionThe remote WU-FTPd server, according to its version number, is vulnerable to a format string attack when running in debug mode.
    last seen2020-06-01
    modified2020-06-02
    plugin id11331
    published2003-03-09
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11331
    titleWU-FTPD Debug Mode Client Hostname Remote Format String
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-016.NASL
    descriptionSecurity people at WireX have noticed a temp file creation bug and the WU-FTPD development team has found a possible format string bug in wu-ftpd. Both could be remotely exploited, though no such exploit exists currently.
    last seen2020-06-01
    modified2020-06-02
    plugin id14853
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14853
    titleDebian DSA-016-3 : wu-ftpd - temp file creation and format string

Statements

contributorJoshua Bressers
lastmodified2006-09-27
organizationRed Hat
statementRed Hat Enterprise Linux 2.1 ships with wu-ftp version 2.6.2 which is not vulnerable to this issue.