CVE Vulnerabilities

CVE-2002-2245

Published: Dec 31, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

Affected Software

Name Vendor Start Version End Version
Ftpd Netbsd 1.5 (including) 1.5 (including)
Ftpd Netbsd 1.5.1 (including) 1.5.1 (including)
Ftpd Netbsd 1.5.2 (including) 1.5.2 (including)
Ftpd Netbsd 1.5.3 (including) 1.5.3 (including)
Ftpd Netbsd 1.6 (including) 1.6 (including)

References