Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kerberos_5 | Mit | 1.1.1 (including) | 1.1.1 (including) |
Kerberos_5 | Mit | 1.2 (including) | 1.2 (including) |
Kerberos_5 | Mit | 1.2.1 (including) | 1.2.1 (including) |
Kerberos_5 | Mit | 1.2.2 (including) | 1.2.2 (including) |
Irix | Sgi | 6.1 (including) | 6.1 (including) |
Irix | Sgi | 6.5.1 (including) | 6.5.1 (including) |
Irix | Sgi | 6.5.2m (including) | 6.5.2m (including) |
Irix | Sgi | 6.5.3 (including) | 6.5.3 (including) |
Irix | Sgi | 6.5.3f (including) | 6.5.3f (including) |
Irix | Sgi | 6.5.3m (including) | 6.5.3m (including) |
Irix | Sgi | 6.5.4 (including) | 6.5.4 (including) |
Irix | Sgi | 6.5.5 (including) | 6.5.5 (including) |
Irix | Sgi | 6.5.6 (including) | 6.5.6 (including) |
Irix | Sgi | 6.5.7 (including) | 6.5.7 (including) |
Irix | Sgi | 6.5.8 (including) | 6.5.8 (including) |
Irix | Sgi | 6.5.10 (including) | 6.5.10 (including) |
Irix | Sgi | 6.5.11 (including) | 6.5.11 (including) |