Lucene search

K
cve[email protected]CVE-2010-0625
HistoryApr 05, 2010 - 4:30 p.m.

CVE-2010-0625

2010-04-0516:30:00
CWE-119
web.nvd.nist.gov
27
cve-2010-0625
buffer overflow
nwftpd.nlm
novell netware
remote authentication
dos
arbitrary code execution

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.29 Low

EPSS

Percentile

96.9%

Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.

Affected configurations

NVD
Node
novellnetware_ftp_serverMatch5.01i
OR
novellnetware_ftp_serverMatch5.01o
OR
novellnetware_ftp_serverMatch5.01w
OR
novellnetware_ftp_serverMatch5.01y
OR
novellnetware_ftp_serverMatch5.02b
OR
novellnetware_ftp_serverMatch5.02i
OR
novellnetware_ftp_serverMatch5.02r
OR
novellnetware_ftp_serverMatch5.02y
OR
novellnetware_ftp_serverMatch5.03b
OR
novellnetware_ftp_serverMatch5.03l
OR
novellnetware_ftp_serverMatch5.04.5
OR
novellnetware_ftp_serverMatch5.04.8
OR
novellnetware_ftp_serverMatch5.04.20
OR
novellnetware_ftp_serverMatch5.04.25
OR
novellnetware_ftp_serverMatch5.05
OR
novellnetware_ftp_serverMatch5.05.04
OR
novellnetware_ftp_serverMatch5.06.04
OR
novellnetware_ftp_serverMatch5.06.05
OR
novellnetware_ftp_serverMatch5.07
OR
novellnetware_ftp_serverMatch5.07.02
AND
novellnetwareMatch5.1
OR
novellnetwareMatch5.1sp2a
OR
novellnetwareMatch5.1sp3
OR
novellnetwareMatch5.1sp4
OR
novellnetwareMatch5.1sp6
OR
novellnetwareMatch6.0
OR
novellnetwareMatch6.0sp1
OR
novellnetwareMatch6.0sp2
OR
novellnetwareMatch6.0sp3
OR
novellnetwareMatch6.5
OR
novellnetwareMatch6.5sp1
OR
novellnetwareMatch6.5sp1.1a
OR
novellnetwareMatch6.5sp1.1b
OR
novellnetwareMatch6.5sp2
OR
novellnetwareMatch6.5sp3
OR
novellnetwareMatch6.5sp4
OR
novellnetwareMatch6.5sp5
OR
novellnetwareMatch6.5sp6
OR
novellnetwareMatch6.5sp7
OR
novellnetwareMatch6.5sp8

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.29 Low

EPSS

Percentile

96.9%