VDB
CVE-2001-0550
CVE-2001-0550
PUBLISHED
CVSS 7.5 HIGH
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
EPSS 60.88% · 98.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
60.88%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| david_madore | ftpd-bsd | 0.3.3, 0.3.2, 0.3.2 |
| washington_university | wu-ftpd | 2.6.0, 2.6.1, 2.6.0 |
| n/a | n/a | n/a, * |
Timeline
- Nov 30, 2001 CVE Published
- Sep 23, 2010 PoC Published
- Jun 20, 2017 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- SuSE-SA:2001:043 vendor-advisory
- 20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability mailing-list
- CA-2001-33 third-party-advisory
- wuftp-glob-heap-corruption(7611) vdb
- MDKSA-2001:090 vendor-advisory
- CLA-2001:442 vendor-advisory
- HPSBUX0107-162 vendor-advisory
- 20010430 some ftpd implementations mishandle CWD ~{ mailing-list
- CSSA-2001-041.0 vendor-advisory
- DSA-087 vendor-advisory
- IMNX-2001-70-036-01 vendor-advisory
- RHSA-2001:157 vendor-advisory
- VU#886083 third-party-advisory
- 3581 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2001-0550 advisory