Vulnerability Description
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smbftpd | Smbftpd | 0.96 |
Related Weaknesses (CWE)
References
- http://debork.se/poc/001_smbftpd.c
- http://osvdb.org/41385
- http://secunia.com/advisories/27014Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=543077Patch
- http://www.securityfocus.com/archive/1/481220/100/0/threaded
- http://www.securityfocus.com/bid/25871ExploitPatch
- http://www.vupen.com/english/advisories/2007/3311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36893
- https://www.exploit-db.com/exploits/4478
- http://debork.se/poc/001_smbftpd.c
- http://osvdb.org/41385
- http://secunia.com/advisories/27014Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=543077Patch
- http://www.securityfocus.com/archive/1/481220/100/0/threaded
- http://www.securityfocus.com/bid/25871ExploitPatch
FAQ
What is CVE-2007-5184?
CVE-2007-5184 is a vulnerability with a CVSS score of 7.5 (HIGH). Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
How severe is CVE-2007-5184?
CVE-2007-5184 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5184?
Check the references section above for vendor advisories and patch information. Affected products include: Smbftpd Smbftpd.