Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-0963
Description:Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
Test IDs: 1.3.6.1.4.1.25623.1.0.52535   1.3.6.1.4.1.25623.1.0.50288   1.3.6.1.4.1.25623.1.0.51327   1.3.6.1.4.1.25623.1.0.53107   1.3.6.1.4.1.25623.1.0.50962   1.3.6.1.4.1.25623.1.0.52875  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-0963
Bugtraq: 20031212 [slackware-security] lftp security update (SSA:2003-346-01) (Google Search)
http://marc.info/?l=bugtraq&m=107126386226196&w=2
Bugtraq: 20031213 lftp buffer overflows (Google Search)
http://marc.info/?l=bugtraq&m=107152267121513&w=2
Bugtraq: 20031217 [OpenPKG-SA-2003.053] OpenPKG Security Advisory (lftp) (Google Search)
http://marc.info/?l=bugtraq&m=107167974714484&w=2
Bugtraq: 20031218 GLSA: lftp (200312-07) (Google Search)
http://marc.info/?l=bugtraq&m=107177409418121&w=2
Conectiva Linux advisory: CLA-2004:800
http://marc.info/?l=bugtraq&m=107340499504411&w=2
Debian Security Information: DSA-406 (Google Search)
http://www.debian.org/security/2004/dsa-406
http://www.mandriva.com/security/advisories?name=MDKSA-2003:116
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180
RedHat Security Advisories: RHSA-2003:403
http://www.redhat.com/support/errata/RHSA-2003-403.html
RedHat Security Advisories: RHSA-2003:404
http://www.redhat.com/support/errata/RHSA-2003-404.html
http://secunia.com/advisories/10525
http://secunia.com/advisories/10548
SGI Security Advisory: 20040101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
SuSE Security Announcement: SuSE-SA:2003:051 (Google Search)
http://www.novell.com/linux/security/advisories/2003_051_lftp.html




© 1998-2024 E-Soft Inc. All rights reserved.