CVE-2001-1413
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
Desbordamiento de búfer basado en la pila en la función comprexx de ncompress 4.2.4 y anteriores, cuando se utiliza en situaciones que cruzan límites de seguridad (como servidores FTP), puede permitir a atacantes remotos ejecutar código de su elección mediante un argumento de nombre de fichero largo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-10-18 CVE Reserved
- 2004-10-20 CVE Published
- 2024-08-08 CVE Updated
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://seclists.org/lists/vuln-dev/2001/Nov/0202.html | Mailing List | |
http://www.kb.cert.org/vuls/id/176363 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10619 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-200410-08.xml | 2017-07-11 | |
http://www.redhat.com/support/errata/RHSA-2004-536.html | 2017-07-11 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2001-1413 | 2004-12-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1616707 | 2004-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ncompress Search vendor "Ncompress" | Ncompress Search vendor "Ncompress" for product "Ncompress" | <= 4.2.4 Search vendor "Ncompress" for product "Ncompress" and version " <= 4.2.4" | - |
Affected
|