CVE-2007-5300 remote denial of service
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
wzdftpd (Debian) |
Fix Released
|
Unknown
|
|||
wzdftpd (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
Stephan Rügamer | ||
Edgy |
Fix Released
|
Undecided
|
Stephan Rügamer | ||
Feisty |
Fix Released
|
Undecided
|
Stephan Rügamer | ||
Gutsy |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Binary package hint: wzdftpd
From The debian bug report (http://
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for wzdftpd.
CVE-2007-5300[0]:
| Off-by-one error in the do_login_loop function in
| libwzd-
| attackers to cause a denial of service (daemon crash) via a long USER
| command that triggers a stack-based buffer overflow. NOTE: some of
| these details are obtained from third party information.
If you fix this vulnerability please also include the CVE id
in your changelog entry.
For further information:
[0] http://
Kind regards
Nico
Related branches
Changed in wzdftpd: | |
status: | New → Fix Committed |
importance: | Undecided → Medium |
Changed in wzdftpd: | |
status: | Unknown → Fix Released |
Changed in wzdftpd: | |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
I'll add some debdiffs for all supported releases.
Gutsy first, because it's 5 to 12pm ;)