CVE Vulnerabilities

CVE-2010-1938

Published: May 28, 2010 | Modified: Jul 29, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 6-stable (including) 6-stable (including)
Freebsd Freebsd 6.4 (including) 6.4 (including)
Freebsd Freebsd 6.4-release (including) 6.4-release (including)
Freebsd Freebsd 6.4-release_p2 (including) 6.4-release_p2 (including)
Freebsd Freebsd 6.4-release_p3 (including) 6.4-release_p3 (including)
Freebsd Freebsd 6.4-release_p4 (including) 6.4-release_p4 (including)
Freebsd Freebsd 6.4-release_p5 (including) 6.4-release_p5 (including)
Freebsd Freebsd 6.4-stable (including) 6.4-stable (including)
Freebsd Freebsd 7.0 (including) 7.0 (including)
Freebsd Freebsd 7.0-beta_4 (including) 7.0-beta_4 (including)
Freebsd Freebsd 7.0-current (including) 7.0-current (including)
Freebsd Freebsd 7.0-pre-release (including) 7.0-pre-release (including)
Freebsd Freebsd 7.0-release (including) 7.0-release (including)
Freebsd Freebsd 7.0-release-p12 (including) 7.0-release-p12 (including)
Freebsd Freebsd 7.0-release-p8 (including) 7.0-release-p8 (including)
Freebsd Freebsd 7.0-release-p9 (including) 7.0-release-p9 (including)
Freebsd Freebsd 7.0-releng (including) 7.0-releng (including)
Freebsd Freebsd 7.0-stable (including) 7.0-stable (including)
Freebsd Freebsd 7.0_beta4 (including) 7.0_beta4 (including)
Freebsd Freebsd 7.0_releng (including) 7.0_releng (including)
Freebsd Freebsd 7.1 (including) 7.1 (including)
Freebsd Freebsd 7.1-pre-release (including) 7.1-pre-release (including)
Freebsd Freebsd 7.1-rc1 (including) 7.1-rc1 (including)
Freebsd Freebsd 7.1-release-p1 (including) 7.1-release-p1 (including)
Freebsd Freebsd 7.1-release-p2 (including) 7.1-release-p2 (including)
Freebsd Freebsd 7.1-release-p4 (including) 7.1-release-p4 (including)
Freebsd Freebsd 7.1-release-p5 (including) 7.1-release-p5 (including)
Freebsd Freebsd 7.1-release-p6 (including) 7.1-release-p6 (including)
Freebsd Freebsd 7.1-stable (including) 7.1-stable (including)
Freebsd Freebsd 7.2 (including) 7.2 (including)
Freebsd Freebsd 7.2-pre-release (including) 7.2-pre-release (including)
Freebsd Freebsd 7.2-stable (including) 7.2-stable (including)
Freebsd Freebsd 8.0 (including) 8.0 (including)
Freebsd Freebsd 8.1-prerelease (including) 8.1-prerelease (including)

References