Vulnerability Description
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yepyep | Mtftpd | 0.1a |
References
- http://unl0ck.org/files/papers/mtftpd.txtExploitURL Repurposed
- http://www.securiteam.com/exploits/5KP0W0AF5K.htmlExploit
- http://www.securityfocus.com/bid/12947Exploit
- http://www.tripbit.org/advisories/TA-040305.txt
- http://unl0ck.org/files/papers/mtftpd.txtExploitURL Repurposed
- http://www.securiteam.com/exploits/5KP0W0AF5K.htmlExploit
- http://www.securityfocus.com/bid/12947Exploit
- http://www.tripbit.org/advisories/TA-040305.txt
FAQ
What is CVE-2005-0958?
CVE-2005-0958 is a vulnerability with a CVSS score of 7.5 (HIGH). Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
How severe is CVE-2005-0958?
CVE-2005-0958 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0958?
Check the references section above for vendor advisories and patch information. Affected products include: Yepyep Mtftpd.