CVE-2000-0574
Last modified
CVE-2000-0574 is a vulnerability of currently unknown severity. FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.. EPSS estimates a 58.87% chance of exploitation in the next 30 days.
Description
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Ftpd | 5.51 |
| Openbsd | Ftpd | 5.60 |
| Washington University | Wu-Ftpd | 2.4.2_beta1 |
| Washington University | Wu-Ftpd | 2.4.2_beta18 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr4 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr5 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr6 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr7 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr8 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr9 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr10 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr11 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr12 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr13 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr14 |
| Washington University | Wu-Ftpd | 2.4.2_beta18_vr15 |
| Washington University | Wu-Ftpd | 2.4.2_vr16 |
| Washington University | Wu-Ftpd | 2.4.2_vr17 |
| Washington University | Wu-Ftpd | 2.5 |
| Washington University | Wu-Ftpd | 2.6 |
References
- http://www.cert.org/advisories/CA-2000-13.htmlPatch, Third Party Advisory, US Government Resource
- http://www.cert.org/advisories/CA-2000-13.htmlPatch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0574?
How severe is CVE-2000-0574?
How do I fix CVE-2000-0574?
Are you affected by CVE-2000-0574?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
