Lucene search

K
cve[email protected]CVE-2006-6576
HistoryDec 15, 2006 - 7:28 p.m.

CVE-2006-6576

2006-12-1519:28:00
CWE-787
web.nvd.nist.gov
80
2
cve-2006-6576
golden ftp server
buffer overflow
denial of service
remote code execution

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.7 High

AI Score

Confidence

High

0.687 Medium

EPSS

Percentile

98.0%

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

Affected configurations

NVD
Node
goldenftpservergolden_ftp_serverMatch1.92

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.7 High

AI Score

Confidence

High

0.687 Medium

EPSS

Percentile

98.0%