Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53827
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 087-1 (wu-ftpd)
Summary:The remote host is missing an update to wu-ftpd;announced via advisory DSA 087-1.
Description:Summary:
The remote host is missing an update to wu-ftpd
announced via advisory DSA 087-1.

Vulnerability Insight:
CORE ST reports that an exploit has been found for a bug in the wu-ftpd
glob code (this is the code that handles filename wildcard expansion).
Any logged in user (including anonymous ftp users) can exploit the bug
to gain root privilege on the server.

This has been corrected in version 2.6.0-6 of the wu-ftpd package.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2001-0550
BugTraq ID: 3581
http://www.securityfocus.com/bid/3581
Bugtraq: 20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=100700363414799&w=2
http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt
Caldera Security Advisory: CSSA-2001-SCO.36
Caldera Security Advisory: CSSA-2002-SCO.1
http://www.cert.org/advisories/CA-2001-33.html
CERT/CC vulnerability note: VU#886083
http://www.kb.cert.org/vuls/id/886083
Conectiva Linux advisory: CLA-2001:442
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000442
Debian Security Information: DSA-087 (Google Search)
http://www.debian.org/security/2001/dsa-087
HPdes Security Advisory: HPSBUX0107-162
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162
Immunix Linux Advisory: IMNX-2001-70-036-01
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01
ISS Security Advisory: 20011129 WU-FTPD Heap Corruption Vulnerability
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3
http://www.redhat.com/support/errata/RHSA-2001-157.html
SuSE Security Announcement: SuSE-SA:2001:043 (Google Search)
http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html
http://www.securityfocus.com/archive/82/180823
XForce ISS Database: wuftp-glob-heap-corruption(7611)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7611
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.