ubuntu · CVE-2007-5300

Quick triage

Priority: low Published: 2007-10-09 18:17:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-5300 low priority: Ubuntu including 1 source packages (wzdftpd), 5 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): released 4, needs-triage 1.

Description:

Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third party information.

cvelogic Threat Intelligence