VDB
CVE-2001-1413
CVE-2001-1413
PUBLISHED
CVSS 7.5 HIGH
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
EPSS 4.77% · 91.2th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.77%
91.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| ncompress | ncompress | 0 |
Timeline
- Oct 20, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- VU#176363 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2001-1413 advisory
- http://seclists.org/lists/vuln-dev/2001/Nov/0202.html url
- http://security.gentoo.org/glsa/glsa-200410-08.xml url
- http://www.redhat.com/support/errata/RHSA-2004-536.html patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10619 technical