// For flags

CVE-2003-0831

ProFTPd 1.2.7/1.2.8 - '.ASCII' File Transfer Buffer Overrun

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.

ProFTPD 1.2.7 a 1.2.9rc2 no traduce adecuadamente los caractéres de nueva línea cuando transfiere caractéres en modo ASCII, permite a atancantes remotos ejecutar código arbitrario mediante un desbordamiento de búfer usando ciertos ficheros.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-09-23 First Exploit
  • 2003-09-24 CVE Reserved
  • 2003-09-25 CVE Published
  • 2024-07-23 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.7
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.7"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.7_rc1
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.7_rc1"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.7_rc2
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.7_rc2"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.7_rc3
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.7_rc3"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.8
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.8"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.8_rc1
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.8_rc1"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.8_rc2
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.8_rc2"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.9_rc1
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.9_rc1"
-
Affected
Proftpd Project
Search vendor "Proftpd Project"
Proftpd
Search vendor "Proftpd Project" for product "Proftpd"
1.2.9_rc2
Search vendor "Proftpd Project" for product "Proftpd" and version "1.2.9_rc2"
-
Affected