CVE-2007-6735
Summary
| CVE | CVE-2007-6735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-05 15:30:00 UTC |
| Updated | 2010-04-06 14:22:00 UTC |
| Description | NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Novell | Netware | All | All | All | All |
| Operating System | Novell | Netware | All | All | All | All |
| Application | Novell | Netware Ftp Server | All | All | All | All |
| Application | Novell | Netware Ftp Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | CONFIRM | bugzilla.novell.com | |
| What fixes are in NWFTPD.NLM v5.10.01, March 26, 2010? | CONFIRM | www.novell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.