CVE Vulnerabilities

CVE-2010-1938

Published: May 28, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd6-stable (including)6-stable (including)
FreebsdFreebsd6.4 (including)6.4 (including)
FreebsdFreebsd6.4-release (including)6.4-release (including)
FreebsdFreebsd6.4-release_p2 (including)6.4-release_p2 (including)
FreebsdFreebsd6.4-release_p3 (including)6.4-release_p3 (including)
FreebsdFreebsd6.4-release_p4 (including)6.4-release_p4 (including)
FreebsdFreebsd6.4-release_p5 (including)6.4-release_p5 (including)
FreebsdFreebsd6.4-stable (including)6.4-stable (including)
FreebsdFreebsd7.0 (including)7.0 (including)
FreebsdFreebsd7.0-beta_4 (including)7.0-beta_4 (including)
FreebsdFreebsd7.0-current (including)7.0-current (including)
FreebsdFreebsd7.0-pre-release (including)7.0-pre-release (including)
FreebsdFreebsd7.0-release (including)7.0-release (including)
FreebsdFreebsd7.0-release-p12 (including)7.0-release-p12 (including)
FreebsdFreebsd7.0-release-p8 (including)7.0-release-p8 (including)
FreebsdFreebsd7.0-release-p9 (including)7.0-release-p9 (including)
FreebsdFreebsd7.0-releng (including)7.0-releng (including)
FreebsdFreebsd7.0-stable (including)7.0-stable (including)
FreebsdFreebsd7.0_beta4 (including)7.0_beta4 (including)
FreebsdFreebsd7.0_releng (including)7.0_releng (including)
FreebsdFreebsd7.1 (including)7.1 (including)
FreebsdFreebsd7.1-pre-release (including)7.1-pre-release (including)
FreebsdFreebsd7.1-rc1 (including)7.1-rc1 (including)
FreebsdFreebsd7.1-release-p1 (including)7.1-release-p1 (including)
FreebsdFreebsd7.1-release-p2 (including)7.1-release-p2 (including)
FreebsdFreebsd7.1-release-p4 (including)7.1-release-p4 (including)
FreebsdFreebsd7.1-release-p5 (including)7.1-release-p5 (including)
FreebsdFreebsd7.1-release-p6 (including)7.1-release-p6 (including)
FreebsdFreebsd7.1-stable (including)7.1-stable (including)
FreebsdFreebsd7.2 (including)7.2 (including)
FreebsdFreebsd7.2-pre-release (including)7.2-pre-release (including)
FreebsdFreebsd7.2-stable (including)7.2-stable (including)
FreebsdFreebsd8.0 (including)8.0 (including)
FreebsdFreebsd8.1-prerelease (including)8.1-prerelease (including)
OpieUbuntudevel*
OpieUbuntujaunty*
OpieUbuntukarmic*
OpieUbuntulucid*

References