9.3

CVE-2010-1938

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreebsdFreebsd Version6 Updatestable
FreebsdFreebsd Version6.4
FreebsdFreebsd Version6.4 Updaterelease
FreebsdFreebsd Version6.4 Updaterelease_p2
FreebsdFreebsd Version6.4 Updaterelease_p3
FreebsdFreebsd Version6.4 Updaterelease_p4
FreebsdFreebsd Version6.4 Updaterelease_p5
FreebsdFreebsd Version6.4 Updatestable
FreebsdFreebsd Version7.0
FreebsdFreebsd Version7.0 Updatebeta_4
FreebsdFreebsd Version7.0 Updatecurrent
FreebsdFreebsd Version7.0 Updatepre-release
FreebsdFreebsd Version7.0 Updaterelease
FreebsdFreebsd Version7.0 Updaterelease-p12
FreebsdFreebsd Version7.0 Updaterelease-p8
FreebsdFreebsd Version7.0 Updaterelease-p9
FreebsdFreebsd Version7.0 Updatereleng
FreebsdFreebsd Version7.0 Updatestable
FreebsdFreebsd Version7.0-release
FreebsdFreebsd Version7.0_beta4
FreebsdFreebsd Version7.0_releng
FreebsdFreebsd Version7.1
FreebsdFreebsd Version7.1 Updatepre-release
FreebsdFreebsd Version7.1 Updaterc1
FreebsdFreebsd Version7.1 Updaterelease-p1
FreebsdFreebsd Version7.1 Updaterelease-p2
FreebsdFreebsd Version7.1 Updaterelease-p4
FreebsdFreebsd Version7.1 Updaterelease-p5
FreebsdFreebsd Version7.1 Updaterelease-p6
FreebsdFreebsd Version7.1 Updatestable
FreebsdFreebsd Version7.2
FreebsdFreebsd Version7.2 Updatepre-release
FreebsdFreebsd Version7.2 Updatestable
FreebsdFreebsd Version8.0
FreebsdFreebsd Version8.1-prerelease
NrlOpie Updatetest1 Version <= 2.4.1
NrlOpie Version2.2
NrlOpie Version2.3
NrlOpie Version2.4
NrlOpie Version2.10
NrlOpie Version2.11
NrlOpie Version2.21
NrlOpie Version2.22
NrlOpie Version2.32
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 39.54% 0.972
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.