LWN.net Logo

wzdftpd: missing input sanitizing

Package(s):wzdftpd CVE #(s):CVE-2005-3081
Created:March 17, 2006 Updated:March 22, 2006
Description: "kcope" discovered that the wzdftpd FTP server lacks input sanitizing for the SITE command, which may lead to the execution of arbitrary shell commands.
Alerts:
Debian DSA-1006-1 2005-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds