6.8

CVE-2010-4652

Exploit
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proftpd ≫ Proftpd Update c Version <= 1.3.3
Proftpd ≫ Proftpd Version 1.2.0
Proftpd ≫ Proftpd Version 1.2.0 Update pre10
Proftpd ≫ Proftpd Version 1.2.0 Update pre9
Proftpd ≫ Proftpd Version 1.2.0 Update rc1
Proftpd ≫ Proftpd Version 1.2.0 Update rc2
Proftpd ≫ Proftpd Version 1.2.0 Update rc3
Proftpd ≫ Proftpd Version 1.2.1
Proftpd ≫ Proftpd Version 1.2.2
Proftpd ≫ Proftpd Version 1.2.2 Update rc1
Proftpd ≫ Proftpd Version 1.2.2 Update rc2
Proftpd ≫ Proftpd Version 1.2.2 Update rc3
Proftpd ≫ Proftpd Version 1.2.3
Proftpd ≫ Proftpd Version 1.2.4
Proftpd ≫ Proftpd Version 1.2.5
Proftpd ≫ Proftpd Version 1.2.5 Update rc1
Proftpd ≫ Proftpd Version 1.2.5 Update rc2
Proftpd ≫ Proftpd Version 1.2.5 Update rc3
Proftpd ≫ Proftpd Version 1.2.6
Proftpd ≫ Proftpd Version 1.2.6 Update rc1
Proftpd ≫ Proftpd Version 1.2.6 Update rc2
Proftpd ≫ Proftpd Version 1.2.7
Proftpd ≫ Proftpd Version 1.2.7 Update rc1
Proftpd ≫ Proftpd Version 1.2.7 Update rc2
Proftpd ≫ Proftpd Version 1.2.7 Update rc3
Proftpd ≫ Proftpd Version 1.2.8
Proftpd ≫ Proftpd Version 1.2.8 Update rc1
Proftpd ≫ Proftpd Version 1.2.8 Update rc2
Proftpd ≫ Proftpd Version 1.2.9
Proftpd ≫ Proftpd Version 1.2.9 Update rc1
Proftpd ≫ Proftpd Version 1.2.9 Update rc2
Proftpd ≫ Proftpd Version 1.2.9 Update rc3
Proftpd ≫ Proftpd Version 1.2.10
Proftpd ≫ Proftpd Version 1.2.10 Update rc1
Proftpd ≫ Proftpd Version 1.2.10 Update rc2
Proftpd ≫ Proftpd Version 1.2.10 Update rc3
Proftpd ≫ Proftpd Version 1.3.0
Proftpd ≫ Proftpd Version 1.3.0 Update a
Proftpd ≫ Proftpd Version 1.3.0 Update rc1
Proftpd ≫ Proftpd Version 1.3.0 Update rc2
Proftpd ≫ Proftpd Version 1.3.0 Update rc3
Proftpd ≫ Proftpd Version 1.3.0 Update rc4
Proftpd ≫ Proftpd Version 1.3.0 Update rc5
Proftpd ≫ Proftpd Version 1.3.1
Proftpd ≫ Proftpd Version 1.3.1 Update rc1
Proftpd ≫ Proftpd Version 1.3.1 Update rc2
Proftpd ≫ Proftpd Version 1.3.1 Update rc3
Proftpd ≫ Proftpd Version 1.3.2
Proftpd ≫ Proftpd Version 1.3.2 Update a
Proftpd ≫ Proftpd Version 1.3.2 Update b
Proftpd ≫ Proftpd Version 1.3.2 Update c
Proftpd ≫ Proftpd Version 1.3.2 Update d
Proftpd ≫ Proftpd Version 1.3.2 Update e
Proftpd ≫ Proftpd Version 1.3.2 Update rc1
Proftpd ≫ Proftpd Version 1.3.2 Update rc2
Proftpd ≫ Proftpd Version 1.3.2 Update rc3
Proftpd ≫ Proftpd Version 1.3.2 Update rc4
Proftpd ≫ Proftpd Version 1.3.3
Proftpd ≫ Proftpd Version 1.3.3 Update a
Proftpd ≫ Proftpd Version 1.3.3 Update b
Proftpd ≫ Proftpd Version 1.3.3 Update rc1
Proftpd ≫ Proftpd Version 1.3.3 Update rc2
Proftpd ≫ Proftpd Version 1.3.3 Update rc3
Proftpd ≫ Proftpd Version 1.3.3 Update rc4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.34% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.debian.org/security/2011/dsa-2191
http://bugs.proftpd.org/show_bug.cgi?id=3536
Patch
Exploit
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053537.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053540.html
http://phrack.org/issues.html?issue=67&id=7#article
http://proftpd.org/docs/RELEASE_NOTES-1.3.3d
http://www.mandriva.com/security/advisories?name=MDVSA-2011:023
http://www.securityfocus.com/bid/44933
http://www.vupen.com/english/advisories/2011/0248
Vendor Advisory
http://www.vupen.com/english/advisories/2011/0331
https://bugzilla.redhat.com/show_bug.cgi?id=670170
Patch
Exploit