CVE-2001-1413

Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncompress:ncompress:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:37

Type Values Removed Values Added
References () http://seclists.org/lists/vuln-dev/2001/Nov/0202.html - () http://seclists.org/lists/vuln-dev/2001/Nov/0202.html -
References () http://security.gentoo.org/glsa/glsa-200410-08.xml - Patch, Vendor Advisory () http://security.gentoo.org/glsa/glsa-200410-08.xml - Patch, Vendor Advisory
References () http://www.kb.cert.org/vuls/id/176363 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/176363 - Third Party Advisory, US Government Resource
References () http://www.redhat.com/support/errata/RHSA-2004-536.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2004-536.html - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10619 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/10619 -

Information

Published : 2004-12-23 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2001-1413

Mitre link : CVE-2001-1413

CVE.ORG link : CVE-2001-1413


JSON object : View

Products Affected

ncompress

  • ncompress