CVE-2001-0187
Summary
| CVE | CVE-2001-0187 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-03-26 05:00:00 UTC |
| Updated | 2017-10-10 01:29:00 UTC |
| Description | Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Washington University | Wu-ftpd | 2.4.1 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18 | All | academ | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr10 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr11 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr12 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr13 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr14 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr15 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr4 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr5 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr6 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr7 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr8 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr9 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta9 | All | academ | All |
| Application | Washington University | Wu-ftpd | 2.4.2_vr16 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_vr17 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.5 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.6 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.1 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18 | All | academ | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr10 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr11 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr12 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr13 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr14 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr15 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr4 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr5 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr6 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr7 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr8 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta18_vr9 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_beta9 | All | academ | All |
| Application | Washington University | Wu-ftpd | 2.4.2_vr16 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.4.2_vr17 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.5 | All | All | All |
| Application | Washington University | Wu-ftpd | 2.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.p... | CONFIRM | ftp.wu-ftpd.org | |
| Debian GNU/Linux -- Security Information -- DSA-016-3 wu-ftpd | DEBIAN | www.debian.org | |
| Home - Conectiva | CONECTIVA | distro.conectiva.com.br | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Wu-Ftpd Debug Mode Client Hostname Format String Vulnerability | BID | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-09-27 | Joshua Bressers | Red Hat Enterprise Linux 2.1 ships with wu-ftp version 2.6.2 which is not vulnerable to this issue. |
There are currently no legacy QID mappings associated with this CVE.