CyberSec.Space Logo
Back to CVE Browser

CVE-2003-0466

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0120%
EPSS Percentile43.85th
PublishedAug 27, 2003
Last ModifiedApr 16, 2026

Vulnerability Description

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

Affected Platforms (CPE)

πŸ“¦
Redhat

Wu Ftpd

= 2.6.1-16
πŸ“¦
Wuftpd

Wu Ftpd

>= 2.5.0 and <= 2.6.2
πŸ’»
Apple

Mac Os X

= 10.2.6
πŸ’»
Apple

Mac Os X Server

= 10.2.6
πŸ’»
Freebsd

Freebsd

>= 4.0 and <= 5.0
πŸ’»
Netbsd

Netbsd

>= 1.5 and <= 1.6.1
πŸ’»
Openbsd

Openbsd

>= 2.0 and <= 3.3
πŸ’»
Sun

Solaris

= 9.0

References & Advisories

Related Vulnerabilities