CVE-2001-1355: Buffer Overflow
Published Jul 20, 2001
·Updated
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.
Affected Software
12 affected components
Netwin DMail=2.5d
Netwin DMail=2.7
Netwin DMail=2.7q
Netwin DMail=2.7r
Netwin DMail=2.8e
Netwin DMail=2.8f
Netwin DMail=2.8g
Netwin DMail=2.8h
Netwin DMail=2.8i
Netwin SurgeFTP=1.0b
Netwin SurgeFTP=2.0a
Netwin SurgeFTP=2.0b
Event History
Jul 20, 2001
CVE Published
04:00 AM
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1355?
CVE-2001-1355 is considered a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2001-1355?
To fix CVE-2001-1355, update affected software packages to the latest version provided by NetWin.
3
Which software versions are affected by CVE-2001-1355?
CVE-2001-1355 affects NetWin DMail versions 2.5d through 2.8e and SurgeFTP versions 1.0b and 2.0a.
4
What type of vulnerability is CVE-2001-1355?
CVE-2001-1355 is a buffer overflow vulnerability.
5
Can CVE-2001-1355 be exploited remotely?
Yes, CVE-2001-1355 can be exploited remotely via specially crafted arguments in specific command executions.