CVE-2005-0484

Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gproftpd:gproftpd:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:55

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=81894 - Exploit, Vendor Advisory () http://bugs.gentoo.org/show_bug.cgi?id=81894 - Exploit, Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200502-26.xml - Vendor Advisory () http://security.gentoo.org/glsa/glsa-200502-26.xml - Vendor Advisory

Information

Published : 2005-03-30 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2005-0484

Mitre link : CVE-2005-0484

CVE.ORG link : CVE-2005-0484


JSON object : View

Products Affected

gproftpd

  • gproftpd