This application requires Javascript for optimal performance.

WuFTP.SITE.EXEC.Attempt

Alias(es)

WuFTP.SITE.EXEC.Attempt.A, WuFTP.SITE.EXEC.Attempt.B

Release Date

Sep 11, 2006

Severity

low

Impact

System compromise: attackers can remotely execute arbitrary commands as root.

Description

This indicates an attempt to exploit a stack overflow vulnerability in Washington University FTP daemon (wu-ftpd).

Wu-ftpd is a popular file transfer protocol daemon from Washington University. Due to inadequate user input validation, a remote attacker can execute arbitrary commands on a target machine via specially crafted FTP commands.

Affected Products

Wu-ftpd versions 2.6.0 and earlier.

Recommended Actions

Upgrade to the latest version of wu-ftpd that does not have the vulnerability.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2000-0573

Reference/s

http://www.fortinet.com/ids/ID101777420
http://www.cert.org/advisories/CA-1995-16.html

Reference: VID-12884