First published: Thu May 24 2001(Updated: )
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.3 | |
Sun SunOS | =5.7 | |
Sun SunOS | =5.5 | |
Sun SunOS | =5.8 | |
Sun SunOS | =5.4 | |
Sun SunOS | =5.5.1 | |
Oracle Solaris SPARC | =2.6 | |
HPE HP-UX | =11.00 | |
Oracle Solaris SPARC | =8 | |
SGI IRIX | >=6.5<=6.5.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0249 has a high severity level due to its potential for remote code execution through heap overflow in the FTP daemon.
To fix CVE-2001-0249, you should apply the appropriate patches provided by Sun/Oracle for affected versions of Solaris.
CVE-2001-0249 affects multiple versions of Solaris, including 5.3, 5.4, 5.5, 5.7, 5.8, and Solaris 8.
Yes, CVE-2001-0249 can be exploited remotely by sending specially crafted FTP LIST commands to the vulnerable server.
CVE-2001-0249 is classified as a heap overflow vulnerability, allowing attackers to execute arbitrary commands.