9.3

CVE-2010-1938

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreebsdFreebsd Version6 Updatestable
FreebsdFreebsd Version6.4
FreebsdFreebsd Version6.4 Updaterelease
FreebsdFreebsd Version6.4 Updaterelease_p2
FreebsdFreebsd Version6.4 Updaterelease_p3
FreebsdFreebsd Version6.4 Updaterelease_p4
FreebsdFreebsd Version6.4 Updaterelease_p5
FreebsdFreebsd Version6.4 Updatestable
FreebsdFreebsd Version7.0
FreebsdFreebsd Version7.0 Updatebeta_4
FreebsdFreebsd Version7.0 Updatecurrent
FreebsdFreebsd Version7.0 Updatepre-release
FreebsdFreebsd Version7.0 Updaterelease
FreebsdFreebsd Version7.0 Updaterelease-p12
FreebsdFreebsd Version7.0 Updaterelease-p8
FreebsdFreebsd Version7.0 Updaterelease-p9
FreebsdFreebsd Version7.0 Updatereleng
FreebsdFreebsd Version7.0 Updatestable
FreebsdFreebsd Version7.0-release
FreebsdFreebsd Version7.0_beta4
FreebsdFreebsd Version7.0_releng
FreebsdFreebsd Version7.1
FreebsdFreebsd Version7.1 Updatepre-release
FreebsdFreebsd Version7.1 Updaterc1
FreebsdFreebsd Version7.1 Updaterelease-p1
FreebsdFreebsd Version7.1 Updaterelease-p2
FreebsdFreebsd Version7.1 Updaterelease-p4
FreebsdFreebsd Version7.1 Updaterelease-p5
FreebsdFreebsd Version7.1 Updaterelease-p6
FreebsdFreebsd Version7.1 Updatestable
FreebsdFreebsd Version7.2
FreebsdFreebsd Version7.2 Updatepre-release
FreebsdFreebsd Version7.2 Updatestable
FreebsdFreebsd Version8.0
FreebsdFreebsd Version8.1-prerelease
NrlOpie Updatetest1 Version <= 2.4.1
NrlOpie Version2.2
NrlOpie Version2.3
NrlOpie Version2.4
NrlOpie Version2.10
NrlOpie Version2.11
NrlOpie Version2.21
NrlOpie Version2.22
NrlOpie Version2.32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 59.85% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C