CVE-2001-1413: Buffer Overflow
Published Oct 20, 2004
·Updated
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
Affected Software
1 affected component
ncompress ncompress<=4.2.4
Remediation
Patch Available
Patch Available
Event History
Oct 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1413?
CVE-2001-1413 has a high severity due to the potential for remote code execution.
2
How do I fix CVE-2001-1413?
To fix CVE-2001-1413, update ncompress to version 4.2.4 or later.
3
What are the potential impacts of CVE-2001-1413?
The potential impacts of CVE-2001-1413 include unauthorized execution of arbitrary code on affected systems.
4
Which versions of ncompress are affected by CVE-2001-1413?
Versions of ncompress prior to 4.2.4 are affected by CVE-2001-1413.
5
In which scenarios is CVE-2001-1413 particularly dangerous?
CVE-2001-1413 is particularly dangerous in situations that cross security boundaries, such as when used by an FTP server.