7.5

CVE-2004-0432

ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proftpd Project ≫ Proftpd Version 1.2.9
Gentoo ≫ Linux Version 0.5
Gentoo ≫ Linux Version 0.7
Gentoo ≫ Linux Version 1.1a
Gentoo ≫ Linux Version 1.2
Gentoo ≫ Linux Version 1.4
Gentoo ≫ Linux Version 1.4 Update rc1
Gentoo ≫ Linux Version 1.4 Update rc2
Gentoo ≫ Linux Version 1.4 Update rc3
Trustix ≫ Secure Linux Version 2.0
Trustix ≫ Secure Linux Version 2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.2% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=108335030208523&w=2
http://bugs.proftpd.org/show_bug.cgi?id=2267
http://marc.info/?l=bugtraq&m=108335051011341&w=2
http://secunia.com/advisories/11527
http://www.mandriva.com/security/advisories?name=MDKSA-2004:041
http://www.securityfocus.com/bid/10252
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16038