|
|
Log in / Subscribe / Register

wzdftpd: denial of service

Package(s):wzdftpd CVE #(s):CVE-2007-5300
Created:January 7, 2008 Updated:January 9, 2008
Description:

From the CVE entry:

Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions and earlier allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow.

Alerts:
Debian DSA-1452-1 wzdftpd 2008-01-06

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds