Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wu-ftpd | Washington_university | 2.4.1 (including) | 2.4.1 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta9 (including) | 2.4.2_beta9 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18 (including) | 2.4.2_beta18 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr4 (including) | 2.4.2_beta18_vr4 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr5 (including) | 2.4.2_beta18_vr5 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr6 (including) | 2.4.2_beta18_vr6 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr7 (including) | 2.4.2_beta18_vr7 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr8 (including) | 2.4.2_beta18_vr8 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr9 (including) | 2.4.2_beta18_vr9 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr10 (including) | 2.4.2_beta18_vr10 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr11 (including) | 2.4.2_beta18_vr11 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr12 (including) | 2.4.2_beta18_vr12 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr13 (including) | 2.4.2_beta18_vr13 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr14 (including) | 2.4.2_beta18_vr14 (including) |
Wu-ftpd | Washington_university | 2.4.2_beta18_vr15 (including) | 2.4.2_beta18_vr15 (including) |
Wu-ftpd | Washington_university | 2.4.2_vr16 (including) | 2.4.2_vr16 (including) |
Wu-ftpd | Washington_university | 2.4.2_vr17 (including) | 2.4.2_vr17 (including) |
Wu-ftpd | Washington_university | 2.5 (including) | 2.5 (including) |
Wu-ftpd | Washington_university | 2.6 (including) | 2.6 (including) |