VDB
CVE-2001-0550
CVE-2001-0550
PUBLISHED
CVSS 7.5 HIGH
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
EPSS 74.65% · 99.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
74.65%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| david_madore | ftpd-bsd | 0.3.3, 0.3.2, 0.3.2 |
| washington_university | wu-ftpd | 2.6.0, 2.6.1, 2.6.0 |
| n/a | n/a | n/a, * |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Jun 20, 2017 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- SuSE-SA:2001:043 vendor-advisory
- IMNX-2001-70-036-01 vendor-advisory
- 20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability mailing-list
- 20010430 some ftpd implementations mishandle CWD ~{ mailing-list
- http://www.cert.org/advisories/CA-2001-33.html patch
- http://www.redhat.com/support/errata/RHSA-2001-157.html patch
- http://www.securityfocus.com/bid/3581 exploit
- http://www.debian.org/security/2001/dsa-087 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7611 technical
- https://nvd.nist.gov/vuln/detail/CVE-2001-0550 advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3 technical
- CLA-2001:442 vendor-advisory
- HPSBUX0107-162 vendor-advisory
- CSSA-2001-041.0 vendor-advisory
- VU#886083 third-party-advisory