CVE-2001-1413

critical

Description

Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/10619

http://www.redhat.com/support/errata/RHSA-2004-536.html

http://www.kb.cert.org/vuls/id/176363

http://security.gentoo.org/glsa/glsa-200410-08.xml

http://seclists.org/lists/vuln-dev/2001/Nov/0202.html

Details

Source: Mitre, NVD

Published: 2004-12-23

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical