Vulnerability Description
Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Luke Mewburn | Lukemftp | <= 1.5 |
| Suse | Suse Linux | 6.4 |
References
- http://www.iss.net/security_center/static/9130.phpPatchVendor Advisory
- http://www.novell.com/linux/security/advisories/2002_18_lukemftp.html
- http://www.iss.net/security_center/static/9130.phpPatchVendor Advisory
- http://www.novell.com/linux/security/advisories/2002_18_lukemftp.html
FAQ
What is CVE-2002-0768?
CVE-2002-0768 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
How severe is CVE-2002-0768?
CVE-2002-0768 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0768?
Check the references section above for vendor advisories and patch information. Affected products include: Luke Mewburn Lukemftp, Suse Suse Linux.