CVE-2004-0185: Buffer Overflow
Published Mar 15, 2004
·Updated
Buffer overflow in the skeychallenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.
Affected Software
1 affected component
Washington University Wu-ftpd=2.6.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 15, 2004
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0185?
CVE-2004-0185 has a high severity due to its potential to allow remote attackers to execute arbitrary code and cause denial of service.
2
How do I fix CVE-2004-0185?
To fix CVE-2004-0185, upgrade to a patched version of wu-ftpd or disable the affected service.
3
Which versions are affected by CVE-2004-0185?
CVE-2004-0185 affects wu-ftpd version 2.6.2.
4
What type of attack does CVE-2004-0185 enable?
CVE-2004-0185 enables a buffer overflow attack through a long s/key request, which can lead to remote code execution.
5
Can CVE-2004-0185 result in denial of service?
Yes, CVE-2004-0185 can cause a denial of service condition due to the buffer overflow vulnerability.