CVE-2012-6067

high

Description

freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

References

http://archives.neohapsis.com/archives/fulldisclosure/2012-12/0011.html

Details

Source: MITRE

Published: 2012-12-04

Updated: 2012-12-05

Type: CWE-287

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH